Cloudflare Changelog[verified]@CFchangelogPatch
Cloudflare’s new WAF release now actively blocks exploits for CVE‑2025‑64459 (Django SQLi) and CVE‑2025‑24893 (XWiki RCE), providing a mitigation for affected applications.
Team Cymru Research[verified]@teamcymru_S2Active Exploitation
The tweet lists the 25 most frequently attempted exploitation CVEs, indicating that these vulnerabilities are currently being targeted in the wild.
motch | セキュリティ🛡️[verified]@motch_devActive Exploitation
CVE-2025-24893, an RCE vulnerability in XWiki Platform, is reported as actively exploited, though no PoC or patch information is provided.
Crowdfense@crowdfenseGeneral
The post lists four new CVEs with short technical descriptors, providing no further detail on PoCs, exploits, patches, or active exploitation.
Bla_Ze 🔥🔥@KuveY81945General
The post describes a successful exploitation chain of two CVEs in a Hack The Box machine, outlining the attack flow but providing no PoC code, patches, or evidence of real‑world attacks.
ExploitGrid@exploitgridGeneral
A daily digest announces several newly disclosed CVEs without providing any detailed technical information, PoC references, or exploitation status.
@pedri77@pedri77Active Exploitation
RondoDox botnet is actively exploiting the unpatched XWiki vulnerability CVE‑2025‑24893 for remote code execution, even though a patch was released in February 2025.
Miguel Vera@mveracfPatch
Cloudflare’s latest WAF update adds detection and blocking rules for CVE‑2025‑64459 (Django SQLi) and CVE‑2025‑24893 (XWiki RCE), providing immediate protection against these critical vulnerabilities.