TechRepublic reports that admin accounts could be covertly hijacked through the abuse of a new critical privilege escalation vulnerability in Apache StreamPipes, tracked as CVE-2025-47411.
The U.S. had 14,486 internet-exposed MongoDB servers exposed to the critical MongoBleed bug, tracked as CVE-2025-14847, making it second only to China, according to Security Affairs.
IBM has warned that exploitation of a critical authentication bypass bug in its API Connect end-to-end application programming interface solution, tracked as CVE-2025-13915, could enable remote app access, The Hacker News reports.
Maximum severity React Server Components and Next.js vulnerability React2Shell, tracked as CVE-2025-55182, has been leveraged by the RondoDox botnet as part of an attack campaign that has been underway since March, reports The Hacker News.
More than 87,000 internet-exposed MongoDB instances could be compromised in ongoing intrusions exploiting the critical MongoBleed flaw, tracked as CVE-2025-14847, which originates from MongoDB Server's management of zlib library-processed network packets for lossless data compression and could be harnessed to facilitate secret exposure, reports BleepingComputer.
Popular Simple Network Management Protocol implementation Net-SNMP has been impacted by a critical vulnerability, tracked as CVE-2025-68615, which could be leveraged to facilitate critical service crashes and system hijacking, reports The Cyber Express.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.