November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from October
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21042 | Out-of-Bounds Write RCE in Samsung Mobile Image Codec (libimagecodec.quram.so) CVE-2025-21042 is an out-of-bounds write (CWE-787) in libimagecodec.quram.so, the Quram image codec library in the image-processing stack of Samsung mobile devices. A remote attacker can trigger the flaw by getting a vulnerable device to decode a crafted image or media file, corrupting memory and potentially executing arbitrary code (the advisory does not specify the exact delivery vector, such as messaging or web content). Successful exploitation allows the attacker to run code on the device, though whether execution is confined to the decoding application or achieves broader privileges is not stated. Any Samsung mobile device using the affected codec is potentially at risk; CISA lists the product only as 'Samsung Mobile Devices' without model or version detail. The flaw is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2025-11-10 (ransomware use unknown), no public PoC is known, and EPSS assigns a 33.2% probability of exploitation within 30 days (98th percentile). Do: Install the latest Samsung security maintenance release (SMR) / monthly security update on all Samsung mobile devices and verify each device's Android security patch level includes the fix for this CVE; per CISA's KEV required action, apply the vendor's mitigations, and federal civilian agencies must follow BOD 22-01 or discontinue use of affected products. Until the update is confirmed, treat untrusted image/media files (e.g., received via messaging or web) as a risk vector on Samsung devices and monitor Samsung's security advisories for the affected-model list. | 9.8 | 33% | KEV |
| masshundreds of millions to roughly a billion Samsung mobile devices in use worldwide (order of magnitude 10^8-10^9) | |
| CVE-2025-58034 | Authenticated OS Command Injection RCE in Fortinet FortiWeb (active exploitation) Fortinet FortiWeb contains an OS command injection flaw (CWE-78) that allows an authenticated attacker to execute unauthorized code on the underlying system by sending crafted HTTP requests or CLI commands. The CVSS vector shows a network-based attack that requires high-privilege (administrative) credentials, so abuse typically follows credential compromise or misuse of a legitimate admin session. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact on the appliance or virtual machine. Affected deployments span every currently supported FortiWeb branch: 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-11-18, EPSS assigns a 55.6% 30-day exploitation probability (99th percentile), and media reports describe it as quietly patched by Fortinet before disclosure under active exploitation. Do: Upgrade FortiWeb to a fixed release in your branch per the Fortinet PSIRT advisory (any release beyond the affected ranges above); because the fix was reportedly included quietly in earlier updates, verify your running version before assuming you are safe. Until patched, restrict administrative access (HTTP/HTTPS management interface and CLI) to trusted networks and review admin logs for unexpected logins or commands; U.S. federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable. | 7.2 | 56% | KEV |
| largetens of thousands of deployed FortiWeb appliances/virtual appliances (public scans typically show thousands-to-tens-of-thousands of FortiWeb instances… | |
| CVE-2025-62215 | Local Privilege Escalation via Race Condition in Microsoft Windows Kernel A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed. Do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available. | 7.0 | 6% | KEV |
| masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide) | |
| CVE-2025-64446 | Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies. Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle. | 9.8 | 92% | KEV PoC |
| large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total… |
Full article1,209 words · extracted from recordedfuture.com · click to collapse
November 2025 saw a significant 69% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 10 vulnerabilities requiring immediate attention, down from 32 in October.
What security teams need to know:
- Fortinet leads concerns: Two critical FortiWeb vulnerabilities (CVE-2025-64446 and CVE-2025-58034) are under active exploitation
- LANDFALL spyware campaign: Threat actors weaponized Samsung's image processing flaw (CVE-2025-21042) for zero-click Android attacks
- Public exploits proliferate: Seven of ten vulnerabilities have public proof-of-concept code available
- OS Command Injection and Out-of-bounds Write were tied as the most common weakness types
Bottom line: The reduced volume shouldn't signal reduced vigilance. November's vulnerabilities demonstrate that threat actors favored quality over quantity in their exploitation campaigns.
Quick Reference: November 2025 Vulnerability Table
All 10 vulnerabilities below were actively exploited in November 2025.
#
Vulnerability
Risk
Score
Affected Vendor/Product
Vulnerability Type/Component
Public PoC
1
99
Gladinet Triofox
CWE-284 (Improper Access Control)
No
2
99
Microsoft Windows 10 and 11; Microsoft Windows Server 2019, 2022, and 2025
CWE-362 (Race Condition), CWE-415 (Double Free)
3
99
Fortinet FortiWeb
CWE-23 (Relative Path Traversal)
4
99
Google Chrome
CWE-843 (Type Confusion)
No
5
99
Fortinet FortiWeb
CWE-78 (OS Command Injection)
6
99
Oracle Identity Manager
CWE-306 (Missing Authentication for Critical Function)
7
99
WatchGuard Fireware OS
CWE-787 (Out-of-bounds Write)
8
99
Samsung Mobile Devices
CWE-787 (Out-of-bounds Write)
9
99
CentOS Web Panel
CWE-78 (OS Command Injection)
10
99
OpenPLC ScadaBR
CWE-79 (Improper Neutralization of Input During Web Page Generation [Cross-site Scripting])
No
Table 1: List of vulnerabilities that were actively exploited in November based on Recorded Future data (Source: Recorded Future)
Key Trends: November 2025
Vendors Most Affected
- Fortinet dominated with two critical FortiWeb vulnerabilities, both enabling remote exploitation
- Microsoft faced a kernel-level race condition affecting all modern Windows versions
- Samsung saw the weaponization of an image processing vulnerability for sophisticated mobile attacks
- Additional affected vendors: Gladinet, Google, Oracle, WatchGuard, CentOS, and Autonomy (OpenPLC)
Most Common Weakness Types
- CWE-78 – OS Command Injection (tied for first)
- CWE-787 – Out-of-bounds Write (tied for first)
- CWE-284 – Improper Access Control
- CWE-362 – Race Condition
- CWE-306 – Missing Authentication for Critical Function
Threat Actor Activity
LANDFALL Android spyware campaign marked November's most sophisticated operation:
- Exploited CVE-2025-21042 for zero-click remote code execution on Samsung devices
- Targeted Middle Eastern countries (Iraq, Iran, Turkey, Morocco) with commercial-grade spyware
- Deployed via weaponized DNG image files through WhatsApp
- Achieved persistent device compromise without user interaction
- Demonstrated advanced anti-analysis and SELinux bypass capabilities
Priority Alert: Active Exploitation
These vulnerabilities demand immediate attention due to confirmed exploitation in the wild.
CVE-2025-64446 | Fortinet FortiWeb
Risk Score: 99 (Very Critical) | CISA KEV: Added November 14, 2025
Why this matters: Unauthenticated attackers can bypass authentication entirely and create administrative accounts. With 4,768 exposed FortiWeb instances globally, this represents a critical internet-facing risk.
Affected versions: FortiWeb 8.0.0-8.0.1, 7.6.0-7.6.4, 7.4.0-7.4.9, 7.2.0-7.2.11, 7.0.0-7.0.11
Immediate actions:
- Apply Fortinet's security updates (8.0.2, 7.6.5, 7.4.10, 7.2.12, or 7.0.12)
- Monitor for POST requests to
/api/v2.0/cmd/system/admin%3F/../../../cgi-bin/fwbcgi - Check for unauthorized admin accounts created since October 2025
- Review logs for Base64-encoded CGIINFO headers
- Disable HTTP/HTTPS on internet-facing interfaces if patching is delayed
Exposure: ~4,768 FortiWeb instances visible on Shodan (Netherlands, US, Germany, Italy, Peru)
CVE-2025-21042 | Samsung Android Devices
Risk Score: 99 (Very Critical) | CISA KEV: Added November 10, 2025
Why this matters: Zero-click exploitation through image files enables complete device compromise without user interaction. The LANDFALL spyware campaign is actively targeting government and business users in the Middle East.
Affected versions: Samsung Galaxy devices running Android 13, 14, and 15
Immediate actions:
- Install Samsung's April 2025 Security Maintenance Release
- Monitor WhatsApp Media directories for suspicious DNG files
- Check for unexpected processes in
/data/data/com.samsung.ipservice/files/ - Review device logs for b.so or l.so module execution
- Educate users about image file risks in messaging apps
Targeted devices: Galaxy S22/S23/S24 series, Z Fold4, Z Flip4
CVE-2025-62215 | Windows Kernel
Risk Score: 99 (Very Critical) | CISA KEV: Added November 12, 2025
Why this matters: Local privilege escalation to SYSTEM allows complete Windows compromise. Attackers are chaining this with initial access techniques for full network penetration.
Affected versions: Windows 10/11 (all versions), Windows Server 2019-2025
Immediate actions:
- Install Microsoft's November 2025 Patch Tuesday updates
- Monitor for unusual memory allocation patterns in kernel space
- Review logs for privilege escalation attempts
- Implement application whitelisting to prevent exploitation tools
- Deploy LAPS and enforce MFA as compensating controls
Technical Deep Dive: Exploitation Analysis
Fortinet FortiWeb Authentication Bypass (CVE-2025-64446)
The dual-flaw design failure: CVE-2025-64446 combines path traversal with authentication bypass in FortiWeb's CGI handling. The vulnerability chain works as follows:
- Path traversal via API endpoints – Unsanitized
../sequences in URIs allow escape to restricted directories - Authentication context injection – The
cgi_auth()function trusts user-supplied HTTP_CGIINFO headers - Administrative impersonation – Base64-encoded JSON in headers creates valid admin sessions
Why this matters: Attackers achieve full administrative access without credentials, enabling complete WAF bypass and potential downstream application compromise.
Insikt Group created a Nuclei template for non-intrusive detection, available to Recorded Future customers. The template checks for vulnerable path traversal without creating accounts or modifying system state.
LANDFALL Android Spyware Campaign (CVE-2025-21042)
Zero-click sophistication: The LANDFALL campaign represents a significant evolution in mobile threats:
- Weaponized DNG files contain embedded ZIP archives with ELF binaries
- Two-stage infection deploys b.so (loader/backdoor) and l.so (privilege escalation)
- SELinux bypass enables persistent system-level access
- Anti-forensics includes cleanup routines and analysis environment detection
Key technical details:
- Exploits Samsung's
libimagecodec.quram.solibrary - Targets specific device models with hardcoded identifiers
- Implements encrypted C2 communication with certificate pinning
- Collects IMEI, IMSI, contacts, and location data
Why this matters: This campaign demonstrates nation-state-level capabilities in commercial spyware, targeting high-value individuals without requiring any user interaction.
Windows Kernel Race Condition (CVE-2025-62215)
Timing-based privilege escalation: The vulnerability exploits improper synchronization in shared kernel resources:
- Concurrent threads access shared data without proper locking
- Race condition enables memory corruption and object reuse
- Successful exploitation grants SYSTEM-level privileges
Why this matters: Local attackers with limited access can achieve complete system control, making this a favorite post-exploitation tool for ransomware operators.
Nuclei Templates from Insikt Group®
Recorded Future customers can access Nuclei templates in the platform for:
- CVE-2025-64446 (Fortinet FortiWeb) - Non-intrusive path traversal detection
Note: All templates are designed for authorized testing only and make no system modifications.
Recorded Future Product Integrations
- Vulnerability Intelligence – Prioritize based on real-world exploitation data
- Attack Surface Intelligence – Discover exposed, internet-facing Fortinet, Samsung, and Windows assets
- Third-Party Intelligence – Monitor vendor vulnerabilities across your third parties
November 2025 Summary
Quality over quantity. Threat actors focused on high-impact vulnerabilities with clear paths to compromise, particularly authentication bypasses and privilege escalations.
Mobile threats evolve. The LANDFALL campaign demonstrates that mobile devices face nation-state-level threats previously reserved for traditional endpoints.
Public exploits accelerate risk. With 70% of vulnerabilities having public PoCs, the window between disclosure and mass exploitation continues to shrink.
Take Action
Ready to see how Recorded Future can help your team detect active exploitation, prioritize patching, and reduce attack surface risk? Explore our demo center to see these capabilities in action, or dive deeper into Insikt Group research for more threat intelligence insights.
About Insikt Group®:
Recorded Future's Insikt Group® is a team of elite analysts, linguists, and security researchers providing actionable intelligence to protect organizations worldwide. Our research combines human expertise with AI-powered analytics to deliver timely, relevant threat intelligence.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/november-2025-cve-landscape