CVE-2025-14027Active Exploitation

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-15: 1Active Exploitation · 2026-03-15: 1Technical Details · 2026-03-15: 103-15
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Liv@atolivia
    Active Exploitation

    2/4 - Mines rely on Rockwell #SCADA (ControlLogix)—CISA KEV: active exploits (CVE-2021-22681 RCE exploited in-wild; CVE-2025-14027 DoS) → digital #sabotage #risk halting production or physical damage.

    Post summary

    CISA identifies CVE-2021-22681 as an actively exploited RCE and CVE-2025-14027 as a DoS affecting Rockwell SCADA systems, highlighting the risk of digital sabotage that could halt mine production or cause physical damage.

    10000158
    1.6K followersView on X

Explore more