NVD disclosure day

Published threat advisories for December 9, 2025

CVE advisoryCRITICAL

CVE-2025-65882

openmptcprouter sysupgrade Helper Arbitrary File Write or Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the system upgrade helper of openmptcprouter, potentially allowing unauthenticated attackers to write arbitrary files or execute commands. This impacts network edge devices, raising concerns about system integrity and unauthorized control if the technology is exposed.

CVE advisoryKnown Exploit

CVE-2025-62221

Microsoft Windows Local Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Cloud Files Mini Filter Driver allows local attackers to elevate privileges. This could impact system integrity and data security for organizations. The vulnerability is actively exploited, posing a realistic business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-59718

Fortinet SSO Authentication Bypass Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Fortinet products allows unauthorized access by bypassing SSO authentication. This impacts affected organizations by potentially exposing systems and data, creating business risk. Organizations should identify affected assets and apply vendor fixes.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-40343

Linux Kernel nvmet-fc Association Deletion Double Schedule Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Linux kernel's nvmet-fc subsystem, allowing a double-free condition during forceful port shutdowns. This could lead to system instability or crashes by improperly deleting data associations. The reachability and scope of affected systems need to be confirmed.

CVE advisoryCRITICAL

CVE-2025-12504

Talent Software UNIS SQL Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL Injection vulnerability in Talent Software UNIS allows attackers to inject malicious commands into databases, potentially leading to unauthorized access or manipulation of sensitive information. This issue is reachable over a network. Confirming if UNIS is deployed is crucial.

CVE advisoryCRITICAL

CVE-2025-11022

Panilux CSRF Command Injection Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A Cross-Site Request Forgery vulnerability in Personal Project Panilux could allow attackers to inject commands if users interact with malicious content. The vendor has disclaimed ownership, leaving a clear path for remediation uncertain. The primary concern is to determine if this project is in use and potentially exp

CVE advisoryCRITICAL

CVE-2022-50666

Linux Kernel RDMA Use-After-Free Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A use-after-free vulnerability exists in the Linux kernel's RDMA subsystem that could lead to system instability or code execution if triggered by a specific network event. This issue arises from improper handling of connection drops, potentially allowing an attacker to reference deallocated memory. Systems using RDMA,

CVE advisoryCRITICAL

CVE-2023-53794

Linux Kernel CIFS Session Reconnect Use-After-Free Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in the Linux kernel's file sharing (CIFS) component related to session reconnection. This flaw could allow an attacker with network access to trigger a use-after-free condition, potentially leading to system compromise. Readers should confirm if their environment uses this technology and