Thirty-nine percent of cloud environments were noted by Wiz to have instances of the JavaScript library React and React-based frameworks, such as Next.js, that are vulnerable to the maximum severity unauthenticated remote code execution flaw, tracked as CVE-2025-55182, which could be subjected to widespread exploitation soon, reports The Register.
Ongoing attacks involving a pair of high-severity Android Framework flaws have prompted their inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, with federal civilian executive branch agencies urged to remediate both security weaknesses by Dec. 23, according to Security Affairs.
Older, unsupported Fortinet FortiWeb 6.x instances could also be compromised in attacks exploiting the operating system command injection flaw, tracked as CVE-2025-58034, and the relative path traversal vulnerability, tracked as CVE-2025-64446, which had been confirmed to affect multiple FortiWeb 7.x and 8.x versions, Cybersecurity Dive reports.
Updates have been released by Google to fix 107 vulnerabilities in Android devices, including a pair of high-severity zero-day issues that may be subjected to limited, targeted exploitation, CyberScoop reports.
SecurityWeek reports that active abuse of the medium-severity OpenPLC ScadaBR cross-site scripting flaw, tracked as CVE-2021-26829, has prompted its inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, with federal agencies urged to remediate the security weakness by Dec. 19.
Old Python packages' bootstrap files are impacted by a security weakness that could enable a domain takeover attack-based supply chain compromise of the Python Package Index, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.