CVE-2025-3248 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
March 20, 2026
Last Seen
July 24, 2026

CVE-2025-3248 is a vulnerability tracked across 6 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed March 20, 2026; most recent activity July 24, 2026.

Related Threat Clusters

  • Critical Langflow RCE Vulnerability Exploited Within 20 Hours

    A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…

    17 articles · Updated March 20, 2026
  • Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats

    Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…

    186 articles · Updated April 2, 2026
  • JADEPUFFER: First Fully Autonomous AI Ransomware Attack Documented

    JADEPUFFER, an autonomous AI-driven ransomware, executed a complete extortion operation exploiting CVE-2025-3248. The attack began with a compromised Langflow instance, allowing the AI to gain initial access without…

    31 articles · Updated July 9, 2026
  • Critical Vulnerabilities in AI and Oracle E-Business Suite Exposed

    Two critical vulnerabilities have been reported, CVE-2025-3248 and CVE-2026-33017, affecting AI systems and Oracle E-Business Suite respectively. CVE-2025-3248 was published on April 7, 2025, and added to CISA KEV for…

    2 articles · Updated June 30, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1541 articles · Updated February 12, 2026
  • Multiple Vulnerabilities Discovered in Substance3D Software

    On March 10, 2026, three critical vulnerabilities were published affecting Substance3D software. CVE-2026-21365 and CVE-2026-27219 both impact Substance3D - Painter versions 11.1.2 and earlier, exposing users to…

    179 articles · Updated March 11, 2026

Recent Intelligence Reports

  • Jadepuffer Agentic Ransomware For Automated Database Extortion — www.sysdig.com · July 24, 2026
  • CVE-2025-3248 — nvd.nist.gov · July 23, 2026
  • Agentic Ransomware Registers First Major Hit — Mbtmag · July 9, 2026
  • JADEPUFFER: First Fully Autonomous AI Ransomware Attack | Let's Data Science — Letsdatascience · July 8, 2026
  • An AI Agent Just Pulled Off a Full Ransomware Attack—and It Didn't Save the Decryption Key — Finance.Biggo · July 3, 2026
  • 1st ‘agentic ransomware’ JADEPUFFER invades database at machine speed — Feeds.Feedburner · July 2, 2026
  • AI Agent Executes 'First' End-To — Rss.Slashdot · July 2, 2026
  • AI Agent Executes End-to-End Ransomware Attack | Let's Data Science — Letsdatascience · July 2, 2026

CVSS v3.1 Breakdown