Drooid Logo
Back to today’s briefing

Story perspectives

Critical Vulnerabilities Disclosed: Urgent Patches Required for Security

11/5/2025

49 8

1 of 1

Story summary
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) added XWiki SolrSearch code execution vulnerability to its Known Exploited Vulnerabilities Catalog after exploitation; vendors have patched it.
  • Disclosed in February 2025 with a CVSS of 9.8, the vulnerability allows attackers with minimal privileges to execute arbitrary commands.
  • A separate local privilege escalation vulnerability affecting VMware Tools has a CVSS score of 7.8.
  • Organizations are urged to apply patches to mitigate these risks.