Security researchers and industry analysts report that the number of published vulnerabilities (CVEs) remains high in late 2025, with a notable year-over-year increase in overall volume, despite a temporary slowdown in November attributed to administrative changes at major CVE Numbering Authorities (CNAs). Kaspersky's Q3 2025 analysis highlights that attackers continue to exploit flaws in widely used software such as WinRAR and Microsoft Office, and that the number of critical vulnerabilities (CVSS > 8.9) remains significant, though slightly lower than the previous year. The data suggests that the vulnerability landscape is both expanding and evolving, with attackers leveraging new and existing flaws for exploitation, particularly in Windows and Linux environments.
Industry commentary emphasizes that fluctuations in monthly CVE counts are often driven by the operational pace of a few large CNAs, rather than a true reduction in underlying risk. The November 2025 dip in CVE disclosures is linked to internal migrations and process slowdowns at organizations like Patchstack, MITRE, and the Linux kernel ecosystem, rather than a decrease in actual vulnerabilities. Security teams are cautioned not to interpret short-term drops in disclosure volume as a sign of stabilization, as the overall trend points to continued growth in vulnerabilities and persistent exploitation by threat actors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Analysts said the November 2025 slowdown in CVE issuance may be temporary and linked in part to Patchstack's internal migration. They expected disclosure output to increase again once the transition is completed.
By late 2025, total CVE publications were running 16.9% higher than in 2024, averaging about 128 new disclosures per day. Analysts noted that disclosure volume and real-world exploitation do not necessarily move in lockstep.
In November 2025, published CVE volume fell 25% compared with the same month in 2024. The decline was attributed mainly to reduced output from major CVE Numbering Authorities such as Patchstack, MITRE, and the Linux kernel ecosystem, rather than a genuine reduction in vulnerabilities.
During Q3 2025, APT activity was characterized by heavy use of zero-days that later saw broader exploitation after disclosure. Common command-and-control frameworks included Metasploit, Sliver, Mythic, and Empire, with rapid adoption of Adaptix C2 also noted.
In Q3 2025, researchers highlighted the ToolShell SharePoint vulnerabilities for enabling authentication bypass and remote code execution. The flaws were cited as a notable part of the quarter's exploitation landscape.
Throughout Q3 2025, exploitation on Windows heavily featured older Microsoft Office Equation Editor and Office vulnerabilities, while Linux detections were dominated by kernel privilege-escalation exploits such as Dirty Pipe. The report says the number of Linux users encountering exploits grew to more than six times the Q1 2023 baseline.
During Q3 2025, the number of published CVEs stayed higher than in prior years, while the share of newly registered critical vulnerabilities was slightly lower than in 2024. The trend was identified through CVE registration data, telemetry, and open-source reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.