News
Linux has a critical vulnerability, even if no one really knows how it is being exploited
Sometimes the cause and what is happening is known, but not how it happens

- September 30, 2025
- Updated: September 30, 2025 at 2:10 PM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added the vulnerability CVE-2025-32463 to its catalog of Known Exploited Vulnerabilities (KEV). This critical flaw affects Sudo versions prior to 1.9.17p1 and has a CVSS score of 9.3, placing it in the high severity category. The first alerts about this vulnerability were issued in July 2025 by researcher Rich Mirch from Stratascale.
A very serious vulnerability to fix
CISA warns that this vulnerability can be exploited by local attackers to execute arbitrary commands with root privileges, taking advantage of the -R (–chroot) option of Sudo, even if such commands are not listed in the sudoers file. This makes it a potentially devastating attack vector for systems that rely on Sudo for privilege management.
According to recent reports, there is evidence of active exploitation of this vulnerability in the real world, although the exact details of how these attacks are being carried out and who is responsible have not yet been clarified. This lack of information may indicate the urgency with which system administrators must act to mitigate the risk.
Agencies of the Federal Civilian Executive Branch (FCEB) are being specifically warned to implement mitigation measures before October 20, 2025, to protect their networks from potential intrusions. In addition to CVE-2025-32463, CISA has also included four other vulnerabilities in its catalog, highlighting the importance of cybersecurity in the current landscape.
System administrators are urged to review their Sudo implementations and apply all necessary updates to ensure the integrity of their networks against this and other imminent threats. Prompt attention to these warnings could make a difference in preventing significant intrusions.
Latest from Softonic
- The showrunner of Andor is preparing a new movie and for that he wants to include two key actors from the MCU
- Oracle may have a serious security issue on its hands that has not been confirmed
- James Gunn confirms that the Marvel and DC universes are more connected than you think
- If a game seems very difficult to you, science has a way for you to get through it and it's not by insisting like an animal
You may also like
- News
ProSpy and ToSpy: the latest spyware threats disguised as messaging applications
Read more
- News
Personalized ads are coming to Facebook and Instagram thanks to conversations with AI
Read more
- News
These are the new releases coming to Crunchyroll this fall
Read more
- News
Elon Musk asks followers to cancel their Netflix subscriptions
Read more
- News
The Russos share an image that could provide clues about the upcoming Avengers movie
Read more
- News
The queer dating reality show on Netflix has come to an end and will not have a third season
Read more