Executive Summary
In October 2025, CISA added two actively exploited vulnerabilities—CVE-2025-24893 in XWiki Platform (Eval Injection) and CVE-2025-41244 in Broadcom VMware Aria Operations and VMware Tools (Privilege Defined with Unsafe Actions)—to its Known Exploited Vulnerabilities (KEV) Catalog. These flaws enable remote attackers to inject malicious code or escalate privileges, presenting substantial risks for the federal enterprise and beyond. The inclusion in the KEV Catalog signals confirmed in-the-wild exploitation and compels agencies to expedite remediation measures under Binding Operational Directive 22-01 to protect critical federal infrastructure networks.
This incident underscores the persistent trend of attackers rapidly leveraging new or previously overlooked vulnerabilities with real-world consequences. As the speed of exploitation shortens and attack surfaces broaden, timely vulnerability management, zero trust practices, and proactive monitoring remain vital to reducing enterprise cyber risk.
Why This Matters Now
The immediate inclusion of these vulnerabilities in the CISA KEV Catalog highlights the urgency of patching in the wake of confirmed active exploitation. Attackers are moving quickly to weaponize public vulnerabilities, increasing the risk of compromise for both public and private sector organizations unless swift, coordinated remediation is prioritized.
Attack Path Analysis
Attackers exploited a newly disclosed vulnerability in a cloud-hosted application (e.g., XWiki or VMware Aria) to gain unauthorized access. Leveraging application flaws or misconfigurations, they escalated privileges and moved laterally within the cloud environment. The adversaries established command and control channels for remote access, enabling further action and persistence. They exfiltrated sensitive data using covert channels or authorized exfil techniques. Ultimately, attackers may have disrupted operations or caused business impact through ransomware, data destruction, or privilege abuse.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited a known vulnerability (e.g., CVE-2025-24893 in XWiki or CVE-2025-41244 in VMware Aria) on an internet-facing cloud resource to gain initial access.
Related CVEs
CVE-2025-24893
CVSS 9.8An eval injection vulnerability in XWiki Platform allows unauthenticated remote code execution via crafted requests to the SolrSearch component.
Affected Products:
XWiki XWiki Platform – < 15.10.11, < 16.4.1, < 16.5.0RC1
Exploit Status:
exploited in the wildCVE-2025-41244
CVSS 7.8A local privilege escalation vulnerability in VMware Aria Operations and VMware Tools allows non-administrative users to gain root access on VMs with SDMP enabled.
Affected Products:
VMware Aria Operations – All versions with SDMP enabled
VMware VMware Tools – All versions with SDMP enabled
Exploit Status:
exploited in the wildReferences:
https://nvd.nist.gov/vuln/detail/CVE-2025-41244https://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Exploitation for Privilege Escalation
Abuse Elevation Control Mechanism
Indicator Removal on Host
Exploitation of Remote Services
Impair Defenses
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 Revision 5 – Flaw Remediation
Control ID: SI-2
PCI DSS v4.0 – Security of Public-Facing Applications
Control ID: 6.3.3
23 NYCRR Part 500 (NYDFS Cybersecurity Regulation) – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management: Preventive Measures
Control ID: Article 8(2)
CISA Zero Trust Maturity Model 2.0 – Continuous Vulnerability Identification and Remediation
Control ID: Vulnerability Management
NIS2 Directive – Incident Prevention and Handling
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory remediation deadlines under BOD 22-01 for XWiki and VMware vulnerabilities enabling privilege escalation attacks.
Information Technology/IT
IT organizations managing VMware Aria Operations and XWiki platforms require immediate patching to prevent eval injection and privilege escalation exploits.
Health Care / Life Sciences
Healthcare systems using affected VMware tools face HIPAA compliance risks from privilege escalation vulnerabilities enabling unauthorized data access.
Financial Services
Banks and financial institutions must prioritize remediation of known exploited vulnerabilities to maintain regulatory compliance and prevent cyberattacks.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2025/10/30/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- NVD - CVE-2025-24893https://nvd.nist.gov/vuln/detail/CVE-2025-24893Verified
- NVD - CVE-2025-41244https://nvd.nist.gov/vuln/detail/CVE-2025-41244Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Network microsegmentation, workload-to-workload access controls, inline IPS, and strict egress policy enforcement would have limited attacker movement, blocked exploitation and exfiltration, and provided deep visibility into abnormal behavior within the cloud environment.
Control: Cloud Firewall (ACF)
Mitigation: Inbound exploit attempts could have been detected and blocked at the perimeter.
Control: Zero Trust Segmentation
Mitigation: Lateral privilege abuse is restricted by least-privilege, identity-based segmentation.
Control: East-West Traffic Security
Mitigation: Internal lateral movement is monitored and blocked between unauthorized workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Malicious outbound connections to attacker C2 infrastructure can be detected or blocked.
Control: Encrypted Traffic (HPE)
Mitigation: Sensitive data exfiltration attempts are prevented or rendered unreadable.
Rapid detection of abnormal behavior enables prompt response before major impact.
Impact at a Glance
Affected Business Functions
- Content Management
- Virtual Machine Management
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive data due to unauthorized code execution and privilege escalation.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy cloud-native firewalls and inline IPS at key ingress points to detect and block exploit attempts against KEV-listed vulnerabilities.
- • Implement Zero Trust Segmentation and least-privilege policies to limit lateral movement and privilege escalation within cloud networks.
- • Enforce strict egress controls, including FQDN filtering and encrypted traffic monitoring, to prevent unauthorized data exfiltration and command & control.
- • Enable continuous east-west traffic inspection and microsegmentation to detect and prevent unauthorized workload-to-workload communications.
- • Integrate threat detection and anomaly response for rapid identification and containment of abnormal activities before they lead to impact.



