Weekly Enterprise Exploitation Trend Report
22-10-2025  to 29-10-2025
The report focuses solely on the exploitation statistics specific to enterprise vendors and their products over the past week, providing valuable insights to prioritize security measures and address emerging threats effectively.
247
247
Actively Exploited Vulnerabilities
107
107
Vendors Actively Exploited
 Apache
 Apache
Most Exploited Vendor
 Microsoft Exchange
 Microsoft Exchange
Most Exploited Product
Top 10 Actively Exploited Vendors
1
Apache
2
Ivanti
3
Atlassian
4
Cisco
5
Oracle
6
Microsoft
7
VMware
8
Palo Alto Networks
9
Citrix
10
Adobe
Top 10 CVEs of 2025 with the Highest EPSS Scores -29-10-2025
1
CVE-2024-27198
- JetBrains TeamCity
 - Authentication Bypass
 - EPSS:0.94579
 - Percentile: 1
 
2
CVE-2023-23752
- Joomla
 - Improper Access Control
 - EPSS: 0.94534
 - Percentile: 1
 
3
CVE-2024-27199
- JetBrains TeamCity
 - Path Traversal
 - EPSS: 0.94489
 - Percentile: 0.99999
 
4
CVE-2023-35078
- Ivanti EPMM
 - Authentication Bypass
 - EPSS: 0.94482
 - Percentile: 0.99998
 
5
CVE-2024-6670
- HTTP/2
 - Denial of Service
 - EPSS:0.94468
 - Percentile: 0.99995
 
6
CVE-2024-23897
- Jenkins
 - Path Traversal
 - EPSS: 0.94466
 - Percentile: 0.99994
 
7
CVE-2023-32315
- Ignite Realtime Openfire
 - SQL Injection
 - EPSS: 0.94441
 - Percentile: 0.9999
 
8
CVE-2023-38035
- Ivanty Sentry
 - Authentication Bypass
 - EPSS: 0.94438
 - Percentile: 0.99987
 
9
CVE-2024-7593
- Ivanti Virtual Traffic Manager
 - Authentication Bypass
 - EPSS:0.94436
 - Percentile: 0.99987
 
10
CVE-2023-46747
- F5 BIG-IP Configuration Utility
 - Authentication Bypass
 - EPSS: 0.94436
 - Percentile: 0.99986
 
Top Exploited CVEs Against Enterprise Applications
CVE-2022-41082
Critical
Critical
Critical
Critical
- Code/command Injection and Execution
 - Exchange
 - Used by Ransomware-United States
 
CVE-2023-20198
Critical
Critical
Critical
Critical
- Code/command Injection and Execution
 - Cisco IOS XE
 - -United States
 
CVE-2023-22515
Critical
Critical
Critical
Critical
- Broken Access Control
 - Confluence
 - Used by Ransomware-Germany
 
CVE-2017-9841
Critical
Critical
Critical
Critical
- Code/command Injection and Execution
 - PHPUnit
 - -United States
 
CVE-2021-42013
Critical
Critical
Critical
Critical
- Path Traversal
 - Apache HTTP Server
 - Used by Ransomware-China
 
CVE-2019-1653
High
High
High
High
- Sensitive Information Disclosure
 - Cisco RV320/RV325
 - -Netherlands
 
CVE-2021-44228
Critical
Critical
Critical
Critical
- Code/command Injection and Execution
 - Log4j
 - Used by Ransomware-United States
 
CVE-2025-0108
High
High
High
High
- Authentication Bypass
 - PAN-OS
 - -United States
 
CVE-2024-24919
High
High
High
High
- Sensitive Information Disclosure
 - Check Point Security Gateway
 - Used by Ransomware-United States
 
CVE-2022-24816
Critical
Critical
Critical
Critical
- Code/command Injection and Execution
 - Geoserver (JAI-EXT)
 - -United States
 
Top 10 Targeted Countries
Top 10 Targeted Countries
China
:
42696
United States
:
33606
Singapore
:
20892
India
:
9167
Brazil
:
7771
Russia
:
4671
Egypt
:
4443
UK
:
4435
Germany
:
3293
Pakistan
:
3224
Actively Exploited Enterprise Vendors
Apache | Ivanti | Atlassian | Cisco | D-Link | Oracle | Microsoft | VMware | Palo Alto Networks | Citrix | Adobe | Draytek | Netgear | Fortinet | F5 | Spring | Progress | QNAP | Wordpress | ZyXEL | Zoho | SAP | SysAid | Realtek | Geoserver | SolarWinds | Synacor | Tenda | SonicWall | Juniper | Sonatype | Aviatrix | JetBrains | Grafana | CrushFTP | Dasan | PHPUnit - Sebastian Bergmann | Check Point | Zyxel/Billion | Pulse Secure | vBulletin | Sunhillo | MobileIron | Micro Focus | Lime Technology | Laravel | Terramaster | ASUS | SaltStack | Fortra | Langflow | Drupal | Hikvision | Webmin | Open Source Matters, Inc/Joomla community | PHP Foundation | Sitecore | nostromo | Telerik | Elastic | Linear | PrimeFaces | mongo-express | Barco/AWIND | LG | WSO2 | CONTEC | MinIO | Roundcube | Dahua | dotCMS | Metabase | Mitel | ForgeRock | NextGen Healthcare | Node.js | Qlik | ownCloud | Yealink | NAKIVO | GLPI (teclib) | TP-Link | Rejetto | Jenkins | IBM | Hitachi Vantara | ConnectWise | wftpserver.com | Commvault | Sophos | Dassualt Systems | PaperCut | Gladinet | FreePBX | Array Networks | RedHat | Kentico | GeoVision | ServiceNow | Cacti | Wazuh | CyberPanel | GNU | Arcadyan | SugarCRM | Cleo | PTZOptics
Most Active Ransomware Groups
Ransomware Posting Frequency by Group - Last 7 Days
Remotely Exploited CISA KEV CVEs Added
These vulnerabilities have been newly added to the Known Exploited Vulnerabilities (KEV) Catalog. Organizations should prioritize addressing them  to mitigate risks.
CVE-2025-54236
CVE-2025-59287
CVE-2025-61932
CVE-2022-48503
CVE-2025-2746
CVE-2025-2747
CVE-2025-33073
CVE-2025-61884
CVE-2025-54253
CVE-2025-47827





