Story perspectives
Urgent: CISA Identifies 5 Critical Vulnerabilities, Immediate Action Required
10/21/2025
1 of 1
Story summary
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to the Known Exploited Vulnerabilities catalog on October 20, 2025, including CVE-2025-61884, a remote, unauthenticated server-side request forgery flaw in Oracle E-Business Suite.
- Organizations must patch by November 10, 2025, or stop using the affected software.
- Other flaws include CVE-2025-33073 in Microsoft Windows and Kentico Xperience CMS.
- CISA urges immediate action to protect against these threats.
