Story perspectives
Critical Vulnerabilities Disclosed: Urgent Patches Required for Security
11/5/2025
49 8
1 of 1
Story summary
- U.S. Cybersecurity and Infrastructure Security Agency (CISA) added XWiki SolrSearch code execution vulnerability to its Known Exploited Vulnerabilities Catalog after exploitation; vendors have patched it.
- Disclosed in February 2025 with a CVSS of 9.8, the vulnerability allows attackers with minimal privileges to execute arbitrary commands.
- A separate local privilege escalation vulnerability affecting VMware Tools has a CVSS score of 7.8.
- Organizations are urged to apply patches to mitigate these risks.
