Find notable cyber news and cases, enriched with sources, timelines, and signals.

CentOS Web Panel remote command execution flaw (CVE-2025-48703)

Vulnerability
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

CentOS Web Panel (CWP) is affected by CVE-2025-48703, a critical remote command execution flaw that lets unauthenticated attackers with a valid username run arbitrary shell commands. CISA says the bug is being actively exploited, and the issue affects all versions before 0.9.8.1204.

Related Happenings

CISA KEV listing for Wing FTP CVE-2025-47813

Public Sector Action
First: 17.03.2026 07:23 Last: 17.03.2026 07:23 Sources 1

About this happening: CISA added **CVE-2025-47813** in **Wing FTP Server** to the **KEV catalog** after evidence of **active exploitation**, putting the flaw under formal government tracking. The listi...

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: **CISA** added **CVE-2025-40551** in **SolarWinds Web Help Desk** to the **KEV catalog** and imposed **federal remediation deadlines**, turning a newly exploited flaw into a compl...

CISA adds WatchGuard Fireware CVE-2025-9242 to KEV catalog

Public Sector Action
First: 13.11.2025 09:23 Last: 13.11.2025 09:23 Sources 1

About this happening: CISA **added** **CVE-2025-9242** in **WatchGuard Fireware** to the **KEV catalog**, signaling **active exploitation** and forcing remediation prioritization. The flaw is an **out-...

Gladinet Triofox actively exploited improper access control flaw (CVE-2025-12480)

Vulnerability
First: 11.11.2025 14:30 Last: 11.11.2025 14:30 Sources 1

About this happening: **Gladinet Triofox** is affected by **CVE-2025-12480**, a **critical improper access control flaw** that let attackers reach restricted setup pages and turn the issue into **code...

CISA KEV remediation deadline for CWP exploit

Public Sector Action
First: 05.11.2025 20:26 Last: 05.11.2025 20:26 Sources 1

How related: The agency has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and is giving federal entities subject to the BOD 22-01 guidance until November 25 to apply available security updates and vendor-provided mitigations, or stop using the product.

About this happening: CISA added **CVE-2025-48703** to the **KEV catalog** and set **November 25** as the remediation deadline for federal entities using **CentOS Web Panel (CWP)**. Agencies covered by...

Timeline

  1. 05.11.2025 20:26 2 articles · 6mo ago

    CentOS Web Panel remote command execution flaw (CVE-2025-48703)

    Initial Disclosure

    **CVE-2025-48703** surfaced as a high-severity CWP command-execution flaw affecting versions before **0.9.8.1204**. The issue was later placed in **CISA’s KEV catalog** after exploitation activity was identified.

    Show sources