NVD disclosure day

Published threat advisories for September 23, 2025

CVE advisoryHIGH

CVE-2025-9900

Libtiff Crafted Image Write-What-Where Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Libtiff allows attackers to write data to arbitrary memory locations by providing a specially crafted TIFF image, potentially leading to code execution or denial of service. This vulnerability is reachable through user interaction with a malicious image file.

CVE advisoryCRITICAL

CVE-2025-9846

Inka.Net Unrestricted File Upload Leading to Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Inka.Net allows command injection through unrestricted file uploads. An attacker could exploit this remotely by uploading a malicious file, potentially leading to arbitrary command execution on the affected system. This issue poses a significant risk due to its critical severity.

CVE advisoryCRITICAL

CVE-2025-9588

Iron Mountain EnVision OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An OS Command Injection vulnerability exists in Iron Mountain's EnVision archiving service, potentially allowing attackers to execute unauthorized commands on affected systems. This could impact confidentiality, integrity, and availability. Determining if this technology is in use and assessing its network exposure is