CyCognito Blog

Your source for exposure management research, product news, and security insights.

Search the Blog

By Amit Sheps

CVE-2025-14733 is a high-severity authentication bypass vulnerability that can allow unauthenticated access to protected web applications and APIs. This blog explains affected assets, potential risk, available fixes, recommended actions, and how CyCognito helps organizations identify and reduce exposure.

Read more about Emerging Threat: CVE-2025-14733 –  Authentication Bypass Vulnerability
By Amit Sheps

CVE-2025-55182 is a critical RCE vulnerability in React Server Components affecting React 19 and Next.js applications. This blog explains what’s impacted, how attackers can exploit it, available patches, recommended actions, and how CyCognito helps organizations identify and prioritize exposed assets.

Read more about Emerging Threat: CVE-2025-55182 (React2Shell) – React Server Components RCE Vulnerability
By Amit Sheps

CVE-2025-41115 is a critical privilege escalation and user impersonation vulnerability in Grafana Enterprise. An attacker who exploits it can impersonate an administrator, modify dashboards and alerts, access connected databases and observability data, and pivot into other integrated systems.

Read more about Emerging Threat: CVE-2025-41115 – Critical SCIM Privilege Escalation in Grafana Enterprise
By Amit Sheps

CVE-2025-64095 is a critical file-upload vulnerability in DNN that allows unauthenticated attackers to overwrite site content and inject malicious code. Learn what’s affected, how to mitigate the risk, and how CyCognito helps identify vulnerable external assets.

Read more about Emerging Threat: CVE-2025-64095 – Critical Unauthenticated File Upload Vulnerability in DNN (DotNetNuke)
By Amit Sheps

CVE-2025-55752 is a path traversal vulnerability in Apache Tomcat that can bypass security controls and, in configurations allowing HTTP PUT, enable malicious file uploads leading to potential remote code execution. Proof-of-concept code is available, and cybersecurity authorities warn exploitation attempts are likely.

Read more about Emerging Threat: Apache Tomcat Vulnerability CVE-2025-55752
By Jason Pappalexis

This month’s CyCognito updates give security teams more precision, clarity, and control in exposure management. With the general availability of Teams for advanced role-based access control and enhanced service evidence for greater detection transparency, users gain deeper insights into their environments. Smarter search, streamlined navigation via the new Quick Start feature, and unified asset management improvements all support faster, more confident decision-making.

Read more about What’s New in CyCognito: July 2025 Platform Enhancements