Log4j, Exchange, Cisco Firepower RCEs Lead Daily CVE Briefing
Critical RCEs in Log4j, Microsoft Exchange, and Cisco Firepower dominate today's security landscape, alongside numerous other high-impact vulnerabilities.

A critical remote code execution vulnerability in Apache Log4j2, CVE-2021-44228, continues to be a significant concern. This flaw, affecting versions 2.0-beta9 through 2.15.0, allows attackers to execute arbitrary code by exploiting JNDI features in configurations and log messages. The vulnerability is easily exploitable and has been widely discussed in security circles, with ongoing efforts to patch and mitigate its impact. As reported by Help Net Security and SANS Internet Storm Center, the widespread use of Log4j makes this a persistent threat.
Microsoft Exchange Server is once again in the spotlight with two critical vulnerabilities, CVE-2021-26855 and CVE-2021-27065, both allowing for remote code execution. These flaws, which have been observed in the wild and are part of ongoing threat actor campaigns, enable attackers to compromise mail servers. The Hacker News and The Register Security have detailed how these vulnerabilities are being leveraged. Tenable Blog also highlighted these as critical in customer environments.
Cisco Secure Firewall devices are targeted by CVE-2025-20333, a critical vulnerability that could allow an authenticated, remote attacker to execute arbitrary code. This flaw affects both Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software. The Hacker News and BleepingComputer have reported on this, with Cisco Talos Intelligence also providing analysis. The vulnerability has been linked to the FIRESTARTER backdoor, as noted by CISA Alerts.
SonicWall Email Security versions, specifically 10.0.9.x, are vulnerable to CVE-2021-20021, a critical flaw that allows an attacker to create an administrative account. This is achieved by sending a crafted HTTP request, posing a significant risk to organizations using this product. Tenable Blog has previously reported on related SonicWall vulnerabilities, indicating a pattern of exploitation.
Several critical VMware vSphere Client vulnerabilities, including CVE-2021-21985 and CVE-2021-21972, allow for remote code execution. These flaws stem from a lack of input validation in the Virtual SAN Health Check plug-in and other vCenter Server plugins. A malicious actor with network access can exploit these to gain control of the underlying system, making patching a high priority.
Microsoft SMBv3 protocol is affected by CVE-2020-0796, a critical remote code execution vulnerability. This flaw impacts both client and server components, allowing attackers to execute code remotely. While an older vulnerability, its critical nature means it remains a significant risk if unpatched.
Ivanti Pulse Connect Secure versions 9.0R3/9.1R1 and higher contain CVE-2021-22893, an authentication bypass vulnerability. This flaw affects the Windows File Share Browser and Pulse Secure Collaboration features, potentially allowing unauthenticated access.
Cisco Systems, Inc. is addressing CVE-2025-20333, a critical vulnerability in their VPN web server for Secure Firewall ASA and FTD software. This flaw could permit an authenticated, remote attacker to execute arbitrary code. The Hacker News and CISA Alerts have highlighted this vulnerability and its association with the FIRESTARTER backdoor.
Metabase is vulnerable to CVE-2026-72898, a critical flaw that allows unauthenticated attackers to inject SQL via the '/reset_password' endpoint, leading to administrator access. CISA Alerts has added this to their catalog of known exploited vulnerabilities, underscoring the urgency for patching.
Fortinet SSL VPNs are susceptible to CVE-2020-12812, an improper authentication vulnerability. This flaw allows users to bypass multi-factor authentication if they are prompted for it, potentially granting unauthorized access. Trend Micro Research has noted this vulnerability in the context of attacks targeting the US public sector.
SonicWall SMA100 products are affected by CVE-2021-20016, a critical SQL-injection vulnerability. This allows unauthenticated remote attackers to access sensitive information such as usernames and passwords. Tenable Blog has previously reported on zero-day exploits targeting SonicWall SMA devices.
Microsoft has several high-severity vulnerabilities impacting its systems. CVE-2021-26411 is a memory corruption vulnerability in Internet Explorer. Additionally, CVE-2021-1675 and CVE-2021-1732 relate to Windows Print Spooler and Win32k respectively, both allowing for remote code execution and elevation of privilege. CVE-2019-1458 is another elevation of privilege vulnerability in the Win32k component. Tenable Blog has highlighted the impact of CVE-2021-1732.
Citrix Systems faces multiple critical vulnerabilities. CVE-2019-19781 in Application Delivery Controller (ADC) and Gateway allows for Directory Traversal. CVE-2019-11634 in Citrix Workspace App for Windows has an incorrect access control issue.
Oracle WebLogic Server has a critical vulnerability, CVE-2019-2725, affecting its Web Services component. This easily exploitable flaw allows unauthenticated attackers to compromise the system.
OpenSLP, as used in VMware ESXi, has a use-after-free issue identified as CVE-2020-3992. A malicious actor with management network access can exploit this vulnerability on affected versions of ESXi.