Skip to content

CVE-2025-23006

CVE

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
December 17, 2025
Last Seen
March 5, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

SonicWall has released a patch for the actively exploited zero-day vulnerability CVE-2025-40602, which affects the Appliance Management Console (AMC) of their devices. This vulnerability allows for deserialization of untrusted data, posing risks to users of SonicWall products. Organizations are advi...

Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors and China being the most prominent. This increase highlights ongoing cybersecurity...

Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government entities globally, deploying custom malware backdoors named 'Line Runner' and 'Line Da...

SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability (CVE-2025-23006). The company advises users to apply patches to mitigate the risk...

Public Exploits

Checking GitHub for proof-of-concept code…