A retrospective on the five most impactful vulnerabilities of 2025, covering CVE-2025-55182 (React Server Components RCE), CVE-2025-31324 (SAP NetWeaver unauthenticated RCE), CVE-2025-0108 (PAN-OS auth bypass), CVE-2025-20188 (Cisco IOS XE hardcoded JWT), and CVE-2025-32433 (Erlang/OTP SSH RCE). The analysis identifies four exploitation phases across the year and highlights that attackers consistently favored unauthenticated access, RCE, and low-complexity paths. A key theme is the shrinking window between vulnerability disclosure and active exploitation, making real-time exposure visibility more critical than severity scoring alone.

8m read timeFrom projectdiscovery.io
Post cover image
Table of contents
A Year of Real-World ExploitationThe Five Vulnerabilities That Defined 2025How Exploitation Played Out in 2025What Attackers Optimized ForHow This Activity Was TrackedWhat 2025 Highlighted for DefendersLooking Ahead