Linuxsecurity C-Kermit Vulnerability in Fedora 43 and 44 Exploited
Article Content
- •C-Kermit vulnerability CVE-2025-68920 confirmed exploited by CISA.
- •Affected versions include C-Kermit prior to 11.0.509 on Fedora 43 and 44.
- •Immediate updates to version 11.0.509 are recommended to mitigate risks.
CISA has confirmed exploitation of a medium buffer overflow vulnerability in C-Kermit, affecting Fedora 43 and 44. The vulnerability, identified as CVE-2025-68920, was published on December 24, 2025. Systems running C-Kermit versions prior to 11.0.509 are at risk. The flaw allows attackers to execute arbitrary code, potentially compromising affected systems. Users are advised to update to version 11.0.509 to mitigate this risk. The updates include various enhancements and fixes, addressing the identified vulnerabilities. The exploit is confirmed to be active in the wild, prompting immediate action from system administrators. CISA's advisory emphasizes the need for organizations to check their systems for the necessary updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-68920 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…