Late summer 2025 delivered a cluster of serious vulnerabilities in software that most organizations trust without a second thought: a file compression utility, a widely deployed application delivery controller, a messaging app, an enterprise password manager and a line of firewalls. Several were exploited in the wild before or shortly after patches appeared.
The individual bugs matter, but the pattern matters more. Attackers go after the tools that sit in privileged positions, such as the edge of the network, the store of every password, or the application on every desktop, because one flaw there opens many doors. This article summarizes each vulnerability and then sets out a practical way to triage and patch when several critical issues land at once.
The vulnerabilities on the radar
WinRAR path traversal (CVE-2025-8088). A flaw in the Windows version of WinRAR let specially crafted archives write files outside the intended folder, including into the Windows Startup folder, so malicious code runs at the next login. ESET reported that the Russia-aligned RomCom group exploited it as a zero-day in spear-phishing campaigns in July 2025. RARLAB fixed it in WinRAR 7.13. Because WinRAR has no automatic updater, vulnerable copies linger on many machines for years. Our dedicated article on the WinRAR zero-day has the details.
Citrix NetScaler (CVE-2025-7775). A memory overflow flaw in NetScaler ADC and NetScaler Gateway allowed remote code execution or denial of service on appliances with certain configurations. Citrix released fixes on August 26, 2025 and confirmed exploitation had been observed; CISA promptly added it to its Known Exploited Vulnerabilities catalog. NetScaler devices sit at the network edge and handle remote access, making them a repeated target.
WhatsApp for iOS and Mac (CVE-2025-55177). An authorization flaw in how WhatsApp synchronized linked devices was chained with an Apple image-processing vulnerability (CVE-2025-43300) in a zero-click attack, meaning victims did not need to tap anything. WhatsApp said the attack was sophisticated and targeted specific users. Both vendors issued fixes in August 2025.
Passwordstate authentication bypass. In August 2025 Click Studios urged customers of its Passwordstate enterprise password manager to upgrade after fixing a flaw that could let an attacker bypass authentication through the product’s emergency access page using a crafted URL. Password vaults are high-value targets; Passwordstate itself suffered a supply-chain attack in 2021 in which its update mechanism was hijacked to deliver malware.
WatchGuard Firebox (CVE-2025-9242). A critical out-of-bounds write in the Fireware OS IKE process could allow an unauthenticated remote attacker to execute code on Firebox firewalls configured for certain IKEv2 VPNs. WatchGuard patched it in September 2025. Firewalls and VPN appliances have been favored ransomware entry points for years.
Why trusted tools are the new front line
- Privileged position. Edge devices face the internet and bridge into internal networks. Password managers hold the keys to everything else.
- Weak visibility. Appliances rarely run EDR, and desktop utilities are often outside central patch management.
- Long tails. Legacy and manually updated software stays vulnerable long after a fix is released, so exploitation continues for months or years.
- Social engineering lures. Flaws like the WinRAR bug still need someone to open a file, so phishing and vulnerability exploitation work together.
How to triage when several critical flaws land at once
Few teams can patch everything immediately. A clear order of operations prevents the most dangerous items from waiting behind the merely urgent:
- Confirm exposure. Use your asset inventory to find which affected products and versions you run and whether they face the internet. You cannot prioritize what you have not inventoried.
- Rank by exploitation and exposure. Flaws listed on CISA’s Known Exploited Vulnerabilities catalog in internet-facing systems come first, then exploited flaws in endpoint software, then everything else by severity.
- Patch edge devices within days, not weeks. If a patch cannot be applied immediately, use vendor mitigations or restrict access to management interfaces and VPN endpoints.
- Look for compromise, not just vulnerability. For exploited edge-device flaws, check logs and vendor indicators of compromise; patching does not remove an attacker who is already in.
- Hunt down desktop stragglers. Use software inventory to find old WinRAR and similar utilities, update or remove them, and consider standardizing on tools that update automatically.
- Protect the vault. Restrict password manager web interfaces to internal networks or VPN, require phishing-resistant MFA, and monitor for unusual access or exports.
- Keep mobile devices current with managed update policies, especially for executives and staff likely to be targeted.
The trade-off is operational risk: fast patching occasionally breaks something, especially on appliances. Test quickly on a non-critical unit, keep configuration backups, and schedule short emergency maintenance windows rather than waiting for the monthly cycle. For the policy side of patch timelines, see Is your organization prepared for stricter patch deadlines?
Building a program that is ready before the next one
Triage works best when the groundwork is already in place. That means a current inventory of hardware and software, including versions, owners and internet exposure; a subscription to vendor advisories and CISA’s catalog feed, routed to someone who will act on them; written service-level targets for patching by severity and exposure; and pre-approved emergency change procedures so critical fixes do not wait for a change board. Operationalized threat intelligence and automated remediation tools help, but only when they feed into this process. Review how each of the last few critical vulnerabilities was handled, measure how long each step took, and fix the slowest one first.
Update (September 2026): The WatchGuard flaw did not stay theoretical. In November 2025 CISA added CVE-2025-9242 to its Known Exploited Vulnerabilities catalog after exploitation was observed, with scans at the time showing tens of thousands of Firebox devices still unpatched. The Passwordstate issue was later assigned CVE-2025-59453.
Frequently asked questions
What is the difference between a zero-day and a critical vulnerability?
A zero-day is a flaw exploited before the vendor has released a fix. A critical vulnerability is one with a severe potential impact, whether or not it is being exploited. The most dangerous combination is a critical flaw with active exploitation.
How fast should we patch internet-facing devices?
For actively exploited flaws, within days. CISA’s deadlines for federal agencies are often two to three weeks, but attackers routinely move faster, so private organizations with exposed systems should aim sooner.
Is it safe to keep using a password manager after a vulnerability?
Yes, a well-managed password manager is still far safer than the alternatives. Patch promptly, limit network access to it, require strong MFA and review its audit logs after any disclosed flaw.
Staying ahead of the next zero-day
Delana Technologies helps organizations build asset inventories, exposure-based patch programs and incident response for edge-device compromises, supported by our cybersecurity compliance services. To review how quickly you can respond to the next critical flaw, call 239.414.5126 or contact us.
Sources: ESET research on RomCom exploitation of CVE-2025-8088 (August 2025); Citrix security bulletin for CVE-2025-7775 (August 26, 2025); WhatsApp and Apple security advisories for CVE-2025-55177 and CVE-2025-43300 (August 2025); Click Studios Passwordstate advisory (August 2025); WatchGuard PSIRT advisory for CVE-2025-9242 (September 2025); CISA Known Exploited Vulnerabilities catalog.
