CVE-2025-3248 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
19
occurrences
First Seen
March 20, 2026
Last Seen
September 7, 2026

Related Threat Clusters

  • Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed

    Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to…

    5 articles · Updated August 31, 2026
  • Critical Langflow RCE Vulnerability Exploited Within 20 Hours

    A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…

    17 articles · Updated March 20, 2026
  • Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats

    Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…

    381 articles · Updated April 2, 2026
  • Multiple Exploits Targeting Android and Web Applications

    A cluster of cybersecurity tools has emerged, targeting various vulnerabilities in Android and web applications. The tools include AndroTickler, designed for penetration testing of Android apps, and exposecheck, which…

    28 articles · Updated September 7, 2026
  • Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching

    BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…

    1495 articles · Updated February 9, 2026
  • Critical Vulnerabilities in AI and Oracle E-Business Suite Exposed

    Two critical vulnerabilities have been reported, CVE-2025-3248 and CVE-2026-33017, affecting AI systems and Oracle E-Business Suite respectively. CVE-2025-3248 was published on April 7, 2025, and added to CISA KEV for…

    2 articles · Updated June 30, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1922 articles · Updated February 12, 2026

Recent Intelligence Reports

  • exposecheck exploit — Sploitus · September 7, 2026
  • Jadepuffer Agentic Ransomware For Automated Database Extortion — www.sysdig.com · September 3, 2026
  • Pwning The Ai Stack — www.vulncheck.com · September 2, 2026
  • Attackers Exploit Critical Langflow and Rails Flaws in Credential — Thehackernews · September 1, 2026
  • CVE-2025-3248 — nvd.nist.gov · July 28, 2026
  • Agentic Ransomware Registers First Major Hit — Mbtmag · July 9, 2026
  • JADEPUFFER: First Fully Autonomous AI Ransomware Attack | Let's Data Science — Letsdatascience · July 8, 2026
  • An AI Agent Just Pulled Off a Full Ransomware Attack—and It Didn't Save the Decryption Key — Finance.Biggo · July 3, 2026

CVSS v3.1 Breakdown