Elastic has issued a critical security advisory for Kibana vulnerability CVE-2025-25012, allowing authenticated attackers to execute arbitrary code, scoring 9.9 on the CVSS scale. The flaw, stemming from prototype pollution in file uploads, affects versions 8.15.0 to 8.17.0. Immediate upgrading to version 8.17.3 is essential to mitigate risks, especially for data security and compliance.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered