Geek-Guy.com

Top 20 Most Exploited Vulnerabilities in 2025–2026

Based on the comprehensive cybersecurity analysis from 2025 and 2026 reports, the following table and ranking detail the top 20 most exploited vulnerabilities.

RankCVE IDVulnerability NameAffected ProductSeverity (CVSS)Primary Impact & Mechanism
1CVE-2025-55182React2ShellReact Server Components10.0 (Critical)Unauthenticated RCE: Insecure deserialization in the RSC Flight protocol allows attackers to execute code (e.g., cryptocurrency miners, malware) without credentials.
2CVE-2025-32433Erlang/OTP Zero-DayErlang/OTP SSH Daemon10.0 (Critical)Pre-Auth RCE: Foundational flaw in SSH protocol parsing affecting OT and telecom infrastructure; enables root access before authentication completes.
3CVE-2025-20333ArcaneDoor (Buffer Overflow)Cisco ASA / FTD9.9 (Critical)RCE (Root): Exploited by state-sponsored actors to implant persistent malware (“RayInitiator”) on network edge devices.
4CVE-2025-59287WSUS DeserializationMicrosoft WSUS9.8 (Critical)System RCE: Unauthenticated attackers exploit unsafe deserialization on ports 8530/8531 to execute code with SYSTEM privileges.
5CVE-2025-5777CitrixBleed 2Citrix NetScaler9.3 (Critical)Session Hijacking: Out-of-bounds read allowing attackers to leak session tokens and memory data; patched with a 24-hour deadline.
6CVE-2025-9242Firebox Out-of-BoundsWatchGuard Firebox9.3 (Critical)Unauthenticated RCE: Stack-based buffer overflow in the IKEv2 VPN protocol allowing remote code execution.
7CVE-2025-32463Sudo Chroot EscalateSudo Utility (Linux/Unix)9.3 (Critical)Privilege Escalation: Race condition allowing local users to gain root access by manipulating the --chroot option.
8CVE-2025-12480Triofox Access BypassGladinet Triofox9.1 (Critical)Improper Access Control: Allows attackers to create admin accounts and execute malicious files; exploited by threat cluster UNC6485.
9CVE-2025-5086Apriso DeserializationDassault Systèmes Apriso9.0 (Critical)Unauthenticated RCE: Exploits unsafe SOAP/HTTP requests in manufacturing operations software to execute arbitrary code.
10CVE-2025-53690Sitecore ViewStateSitecore Experience Platform9.0 (Critical)RCE: Deserialization flaw leveraging exposed sample machine keys to execute code; confirmed exploitation by Mandiant.
11CVE-2025-4664Chrome Cross-Origin LeakGoogle Chrome8.8 (High)Data Leak: Allows bypass of referrer policies to leak cross-origin data; widely exploited in the wild.
12CVE-2025-10585V8 Type ConfusionGoogle Chrome8.8 (High)RCE: Memory corruption in the V8 JavaScript engine allowing remote code execution via malicious web pages.
13CVE-2025-48384Git File WriteGit (macOS/Linux)8.1 (High)Arbitrary File Write: Case-sensitivity flaw in configuration parsing allows attackers to write files outside the repo during a clone operation.
14CVE-2025-62221Cloud Files Driver UAFWindows Cloud Files Driver7.8 (High)Privilege Escalation: Use-after-free vulnerability allowing local attackers to gain SYSTEM privileges without user interaction.
15CVE-2025-6218WinRAR Path TraversalWinRAR7.8 (High)RCE: Flaw allowing malicious archives to extract files to arbitrary locations (e.g., Startup folder); exploited by APT groups like Bitter.
16CVE-2025-41244Aria Tools PrivEscVMware Aria / Tools7.8 (High)Local PrivEsc: Untrusted search path vulnerability used by Chinese state actors (UNC5174) to gain root access on VMs.
17CVE-2025-62215Kernel Race ConditionWindows Kernel7.0 (High)Privilege Escalation: Race condition leading to double-free memory corruption; used for lateral movement and credential harvesting.
18CVE-2025-20362ArcaneDoor (Auth Bypass)Cisco ASA / FTD6.5 (Medium)Auth Bypass: Used in a chain with CVE-2025-20333 to grant unauthenticated attackers access to restricted VPN endpoints.
19CVE-2025-48633Android Info DisclosureAndroid FrameworkHighSandbox Bypass: Allows malicious apps to access sensitive system memory; targeted exploitation by state actors.
20CVE-2025-48572Android Priv EscalationAndroid FrameworkHighPrivilege Escalation: Permissions bypass allowing background apps to launch unauthorized activities; often chained with CVE-2025-48633.

Comments are closed.