Security Affairs newsletter Round 529 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28771 | Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies. Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use. | 9.8 | 99% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate | |
| CVE-2025-23121 | Authenticated Domain-User RCE in Veeam Backup & Replication CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix. Do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation. | 8.8 | 22% |
| mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations) | ||
| CVE-2025-3248 | Unauthenticated RCE in Langflow /api/v1/validate/code Langflow, an open-source visual framework for building LLM and agentic AI applications, contains a missing authentication flaw (CWE-306) in its /api/v1/validate/code endpoint. A remote attacker with network reachability to the endpoint can send crafted HTTP requests without any credentials, causing arbitrary code execution on the server. Successful exploitation yields code execution under the application's privileges, enabling data theft, backdoor installation, and, per CISA, ransomware deployment. Any running Langflow instance is affected; the tool is typically self-hosted by development teams building AI workflows, so real-world exposure depends on whether each instance is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-05-05 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), and a public PoC is available. Do: Upgrade Langflow to the latest patched release identified in the vendor's advisory; federal agencies must apply mitigations per vendor instructions under BOD 22-01 or discontinue use if mitigations are unavailable. Until patched, restrict network access to the /api/v1/validate/code endpoint via reverse-proxy authentication, firewall rules, or VPN placement, and avoid exposing Langflow directly to the internet. Because ransomware use is confirmed, review access and process-execution logs for signs of prior compromise. | 9.8 | 100% | KEV ransomware PoC ×2 |
| moderatetens of thousands of self-hosted deployments, with likely only hundreds to low thousands directly exposed to the internet |
Full article421 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
WestJet probes cybersecurity incident affecting app and internal systems
Europe-wide takedown hits longest-standing dark web drug market
Zoomcar Says Hackers Accessed Data of 8.4 Million Users
Krispy Kreme says November data breach impacts over 160,000 people
Cyberattack pushes German napkin company into insolvency
Infrastructure Laundering: Blending in with the Cloud
Qilin ransomware top dogs treat their minions to on-call lawyers for fierier negotiations
Malware
Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet
2025 Blockchain and Cryptocurrency Threat Report: Malware in the Open Source Supply Chain
Fake Minecraft mods distributed by the Stargazers Ghost Network to steal gamers’ data
Threat actor Banana Squad exploits GitHub repos in new campaign
Your Mobile App, Their Playground: The Dark side of the Virtualization
Hacking
GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771
CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability
Critical Veeam Backup & Replication CVE-2025-23121
Iran’s Largest Crypto Exchange Targeted in $90m Hack
The 16-billion-record data breach that no one’s ever heard of
Qualys TRU Uncovers Chained LPE: SUSE 15 PAM to Full Root via libblockdev/udisks
Intelligence and Information Warfare
Predator Still Active, with New Client and Corporate Links Identified
Washington Post investigating cyberattack on journalists’ email accounts, source says
Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict
Threat Group Targets Companies in Taiwan
Internet collapses across Iran, say web-monitoring firms
Viasat identified as victim in Chinese Salt Typhoon cyberespionage, Bloomberg News reports
Iran’s Cyber Army: Missing in Action
Countering AI Chip Smuggling Has Become a National Security Priority
Feeling Blue(Noroff): Inside a Sophisticated DPRK Web3 Intrusion
Iran’s government says it shut down internet to protect against cyberattacks
Cybersecurity
The Impact of Artificial Intelligence on the Cybersecurity Workforce
The AI Arms Race: Deepfake Generation vs. Detection
Managing Serial-to-Ethernet Exposures in Modern OT Networks
No, the 16 billion credentials leak is not a new data breach
Defending the Internet: how Cloudflare blocked a monumental 7.3 Tbps DDoS attack
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179208/breaking-news/security-affairs-newsletter-round-529-by-pierluigi-paganini-international-edition.html