Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
standards-framework-updateactively-exploited-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerability

Trends in Vulnerability Disclosures and Exploitation in Late 2025

Updated 3mo agoFirst seen Dec 5, 20252 sources

Security researchers and industry analysts report that the number of published vulnerabilities (CVEs) remains high in late 2025, with a notable year-over-year increase in overall volume, despite a temporary slowdown in November attributed to administrative changes at major CVE Numbering Authorities (CNAs). Kaspersky's Q3 2025 analysis highlights that attackers continue to exploit flaws in widely used software such as WinRAR and Microsoft Office, and that the number of critical vulnerabilities (CVSS > 8.9) remains significant, though slightly lower than the previous year. The data suggests that the vulnerability landscape is both expanding and evolving, with attackers leveraging new and existing flaws for exploitation, particularly in Windows and Linux environments.

Industry commentary emphasizes that fluctuations in monthly CVE counts are often driven by the operational pace of a few large CNAs, rather than a true reduction in underlying risk. The November 2025 dip in CVE disclosures is linked to internal migrations and process slowdowns at organizations like Patchstack, MITRE, and the Linux kernel ecosystem, rather than a decrease in actual vulnerabilities. Security teams are cautioned not to interpret short-term drops in disclosure volume as a sign of stabilization, as the overall trend points to continued growth in vulnerabilities and persistent exploitation by threat actors.

Share:
Trends in Vulnerability Disclosures and Exploitation in Late 2025
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Dec 4, 20257mo ago

Patchstack migration cited as likely cause of temporary disclosure slowdown

Analysts said the November 2025 slowdown in CVE issuance may be temporary and linked in part to Patchstack's internal migration. They expected disclosure output to increase again once the transition is completed.

2025 CVE publication rate runs well above 2024 levels

By late 2025, total CVE publications were running 16.9% higher than in 2024, averaging about 128 new disclosures per day. Analysts noted that disclosure volume and real-world exploitation do not necessarily move in lockstep.

Nov 30, 20257mo ago

November 2025 CVE count drops 25% year over year

In November 2025, published CVE volume fell 25% compared with the same month in 2024. The decline was attributed mainly to reduced output from major CVE Numbering Authorities such as Patchstack, MITRE, and the Linux kernel ecosystem, rather than a genuine reduction in vulnerabilities.

Sep 30, 20259mo ago

APT actors in Q3 2025 favor zero-days and common C2 frameworks

During Q3 2025, APT activity was characterized by heavy use of zero-days that later saw broader exploitation after disclosure. Common command-and-control frameworks included Metasploit, Sliver, Mythic, and Empire, with rapid adoption of Adaptix C2 also noted.

ToolShell SharePoint flaws highlighted as active Q3 2025 threat

In Q3 2025, researchers highlighted the ToolShell SharePoint vulnerabilities for enabling authentication bypass and remote code execution. The flaws were cited as a notable part of the quarter's exploitation landscape.

Attackers continue exploiting legacy Windows and Linux flaws in Q3 2025

Throughout Q3 2025, exploitation on Windows heavily featured older Microsoft Office Equation Editor and Office vulnerabilities, while Linux detections were dominated by kernel privilege-escalation exploits such as Dirty Pipe. The report says the number of Linux users encountering exploits grew to more than six times the Q1 2023 baseline.

Q3 2025 CVE volume remains elevated year over year

During Q3 2025, the number of published CVEs stayed higher than in prior years, while the share of newly registered critical vulnerabilities was slightly lower than in 2024. The trend was identified through CVE registration data, telemetry, and open-source reporting.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Trends in Vulnerability Disclosures and Exploitation in Late 2025 | Mallory