A series of critical vulnerabilities have been disclosed affecting a wide range of popular software platforms, including WordPress plugins, web frameworks, developer tools, and enterprise applications. Notable issues include unauthenticated remote code execution (RCE) flaws in Next.js (CVE-2025-66478), WordPress core (CVE-2025-6389), and the ACF Extended plugin (CVE-2025-13486), as well as privilege escalation and authentication bypass vulnerabilities in the WP Directory Kit plugin (CVE-2025-13390) and cPanel. Several of these vulnerabilities are reported to be under active exploitation, with proof-of-concept code available for some, increasing the urgency for immediate patching and mitigation.
Other significant disclosures include a high-severity flaw in Vim for Windows (CVE-2025-66476) allowing arbitrary code execution, a critical SQL injection chain in Synology BeeStation, and a directory traversal vulnerability in cPanel that could lead to full server takeover. Additional advisories cover issues in lz4-java, Longwatch OT surveillance, Django, Elementor, Apache Struts, nopCommerce, and OpenVPN, with many rated as critical or high severity by CVSS. Organizations are strongly advised to review affected products and apply security updates promptly to mitigate the risk of exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
A critical WordPress vulnerability, CVE-2025-6389, was disclosed as allowing unauthenticated remote code execution, with reports that attackers were already actively exploiting the flaw.
A critical remote code execution flaw in Next.js, CVE-2025-66478, was disclosed with a CVSS score of 10.0, indicating maximum severity and significant risk to affected deployments.
A high-severity Vim for Windows vulnerability, CVE-2025-66476, was reported as risking arbitrary code execution when users interact with compromised folders.
A Synology BeeStation exploit chain combining SQL injection with a novel dirty file write technique was disclosed as leading to root remote code execution, and a proof-of-concept was made available.
CVE-2025-13390 was published for WP Directory Kit versions through 1.4.4, describing a predictable auto-login token weakness that allows unauthenticated attackers to bypass authentication and gain administrative access.
A critical flaw in the ACF Extended WordPress plugin, CVE-2025-13486, was disclosed as allowing unauthenticated remote code execution and affecting roughly 100,000 sites.
A critical cPanel vulnerability with CVSS 9.3 was reported as enabling directory traversal and local privilege escalation, potentially leading to full server takeover in shared hosting environments.
A critical Elementor plugin vulnerability, CVE-2025-8489, was disclosed with a CVSS score of 9.8 and reports of active exploitation enabling unauthenticated administrator takeover.
A vulnerability in Django, tracked as CVE-2025-13372, was reported as allowing SQL injection through PostgreSQL FilteredRelation handling.
CISA issued a warning for CVE-2025-13658, a critical Longwatch vulnerability rated CVSS 9.8 that could allow unauthenticated attackers to gain SYSTEM-level control of OT surveillance deployments.
A high-severity vulnerability, CVE-2025-12183, was reported in the discontinued lz4-java library, with users urged to migrate to a community-maintained fork because the original project is no longer maintained.
CVE-2025-11699 in nopCommerce was disclosed as a session management flaw that could allow attackers to reuse admin session cookies after logout and take over administrator accounts.
A report disclosed critical OpenVPN vulnerabilities including a heap over-read rated CVSS 9.1 and an HMAC bypass issue that could enable denial-of-service attacks, indicating fixes were made available.
A new Apache Struts vulnerability, CVE-2025-64775, was identified and reported as a file leak issue that could let attackers exhaust disk space on affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.