NVD disclosure day

Published threat advisories for December 23, 2025

CVE advisoryCRITICAL

CVE-2025-67109

Eclipse Cyclone DDS Certificate Check Bypass Executes Commands as System.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Eclipse Cyclone DDS allows attackers to bypass certificate checks, potentially leading to command execution with system privileges. This affects systems relying on this middleware for secure communication, particularly if exposed to external networks, and could impact data integrity and unauthorized

CVE advisoryCRITICAL

CVE-2025-67108

eProsima Fast-DDS Ticket Revocation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

eProsima Fast-DDS, a communications middleware, has a critical vulnerability due to improper ticket revocation validation, which can lead to insecure communications. If reachable, this could allow unauthorized access and modification of exchanged data. Confirming the relevance and exposure of Fast-DDS deployments is cr

CVE advisoryCRITICAL

CVE-2025-68341

Linux Kernel veth XDP Race Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A race condition in the Linux kernel's virtual Ethernet (veth) component can occur during concurrent network packet processing involving XDP and BPF contexts. This vulnerability could lead to system instability or unexpected behavior if multiple network instances attempt to process packets simultaneously, disrupting th