CVE-2025-21727 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 19, 2025
Last Seen
February 18, 2026

CVE-2025-21727 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

CVE-2025-21727 is a vulnerability tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 19, 2025; most recent activity February 18, 2026.

Related Threat Clusters

  • Multiple CVEs Addressed in Microsoft Security Updates

    Microsoft has published information regarding two critical vulnerabilities identified as CVE-2025-21715 and CVE-2025-21727. Both vulnerabilities involve use-after-free (UAF) issues in the dm9000 and padata drivers,…

    5 articles · Updated February 18, 2026
  • Linux Kernel Vulnerabilities Expose Sensitive Information via VMSCAPE

    A series of vulnerabilities in the Linux kernel, identified by researchers Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi, allow attackers in guest virtual machines to potentially expose sensitive…

    90 articles · Updated November 26, 2025
  • Linux Kernel Vulnerability (VMSCAPE) Exposes Host OS Information

    A vulnerability in the Linux kernel, identified as VMSCAPE, allows attackers in guest VMs to potentially expose sensitive information from the host operating system. Discovered by researchers Jean-Claude Graf, Sandro…

    44 articles · Updated November 13, 2025

Recent Intelligence Reports

  • CVE-2025-21727 padata: fix UAF in padata_reorder — Api.Msrc.Microsoft · February 18, 2026
  • Ubuntu 20.04: Linux Kernel Critical Issue VMSCAPE CVE-2025 — Linuxsecurity · November 19, 2025
  • Ubuntu 20.04 LTS: USN-7874 — Linuxsecurity · November 19, 2025

Frequently asked questions

What is CVE-2025-21727?

CVE-2025-21727 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.

Is CVE-2025-21727 still active?

The most recent intelligence report mentioning CVE-2025-21727 on ThreatCluster is dated February 18, 2026. Activity was first observed November 19, 2025, giving a tracked span from then to February 18, 2026.

What is CVE-2025-21727 associated with?

Across ThreatCluster reporting, CVE-2025-21727 most frequently co-occurs with Data Breach, Amazon Web Services, Google Cloud Platform, Ubuntu, CVE-2023-52854, among 12 tracked related entities.

What are the latest developments involving CVE-2025-21727?

The most significant recent cluster is “Multiple CVEs Addressed in Microsoft Security Updates” (5 articles · Updated February 18, 2026). CVE-2025-21727 appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2025-21727?

CVE-2025-21727 appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown