Story perspectives
Critical Security Flaws Uncovered: CVEs Threaten Major Software
10/6/2025
1 of 1
Story summary
- A zero-day in Sudo (CVE-2025-32463) enables local privilege escalation to root.
- A proof-of-concept exploit for CVE-2025-32463 affecting Sudo versions 1.9.14–1.9.17 has been released.
- Oracle E-Business Suite vulnerability CVE-2025-61882 allows unauthenticated remote code execution with CVSS 9.8.
- Redis CVE-2025-49844 use-after-free enables authenticated attackers to execute code via Lua scripts.
- QNAP NetBak Replicator CVE-2025-57714 enables unauthorized code execution with local user access.
