NVD disclosure day

Published threat advisories for October 15, 2025

CVE advisoryKnown Exploit

CVE-2025-53521

BIG-IP APM Remote Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in F5 BIG-IP Access Policy Manager allows for remote code execution when specific malicious traffic is processed. This flaw enables unauthorized actors to gain control of affected systems, posing a risk of data compromise and business disruption. Organizations should prioritize assessing their exposure

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-39975

Linux Kernel SMB Client Index Reference Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's SMB client can mishandle command responses due to incorrect index referencing, potentially causing out-of-bounds memory access. This affects how command results are processed. Uncertainty exists regarding the exploitability and business impact of this issue.

CVE advisoryCRITICAL

CVE-2023-7305

SmartBI Unrestricted File Upload Leads to Remote Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

SmartBI business intelligence software has an unrestricted file upload vulnerability in its RMIServlet. Attackers can exploit this to execute arbitrary code on the host system, a flaw for which a fix has been released and which is actively being exploited.