As of 2026-07-28, CVE-2025-20362 has substantial public exploitation evidence: listed in CISA KEV and listed in ENISA EUVD (exploited). Most recent observation: 2025-09-25.
Every public observation ESIP has recorded for this CVE, with its source and date. Follow any one to the original evidence.
| Observation | Source | Date | |
|---|---|---|---|
| Listed in CISA KEV | CISA KEV | 2025-09-25 | View → |
| Listed in ENISA EUVD (exploited) | ENISA EUVD (Exploited) | 2025-09-25 | View → |
This is one exposure signal: it describes an exposure class, not any one organization's assets. The MITRE ATT&CK techniques mapped to it:
The MITRE CWE weakness type classified for this exposure class:
| Remediation due date | 2025-09-26 |
|---|---|
| Required action | The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. |
| Known ransomware campaign use | None recorded |
ESIP's current exposure signal for this CVE, its lifecycle state, trend, velocity, and corroboration, is available through the commercial API.
Get the assessment →Public evidence is not the whole picture. Limited or absent observed evidence is not the same as safety.
Related CVEs: those that share an ATT&CK technique or CWE weakness with this one.
Data provided by ESIP / ZenzizenSec — www.exposuresignal.io · as of 2026-07-28