s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2025-8903

📛 CVE Title

CVE-2025-8903

Description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a reservation duplicate of CVE-2026-2052 Notes: All CVE users should reference CVE-2026-2052 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Overview

State
REJECTED
Assigner (CNA)
Wordfence
CVSS severity
null
CVSS score
CVSS 9.8 / 10 9.8 9.8 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
9.8 / 10 NULL source: CNA overview
CWE(s)
Reserved
2025-08-12
Published
Last updated
2026-05-01 21:20 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/8xxx/CVE-2025-8903.json
Linked Threat
CVE-2025-8903 — CVE-2025-8903

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-01 20:16:20 UTC
NVD last modified
2026-05-01 20:16:20 UTC

NVD / KEV / EPSS data refreshed 2026-05-25 21:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (2)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (19)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cyberpress.org

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, issuing an urgent remediation directive for federal agencies with a due date of June 3, 2026.

    2026-05-23 18:36 UTC
  • web:krebsonsecurity.com

    Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.

    2026-05-23 18:36 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-05-23 18:36 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-23 18:36 UTC
  • web:www.cisa.gov

    Updated October 29, 2025 : CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025 ), CVE - 2025 -59287

    2026-05-23 18:36 UTC
  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

    2026-05-23 18:36 UTC
  • web:www.lansweeper.com

    Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday October 2025 summary.

    2026-05-23 18:36 UTC
  • web:www.rapid7.com

    Microsoft has published 172 new vulnerabilities, including six zero-day vulnerabilities. Windows 10 moves past the end of support, sort of. Critical RCE in Windows Server Update Service.

    2026-05-23 18:36 UTC
  • web:www.techrepublic.com

    Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.

    2026-05-23 18:36 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-05-23 18:36 UTC
  • web:cybersecuritynews.com

    Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release.

    2026-06-03 07:49 UTC
  • web:epatch.pa.gov

    Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...

    2026-06-03 07:49 UTC
  • web:msrc.microsoft.com

    Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.

    2026-06-03 07:49 UTC
  • web:patchnashville.com

    Patch was born out of a love of children's fashion and classic yet modern gifting. The goal was to create a timeless yet modern boutique with a playful touch featuring children's clothing, gifts, & accessories. My hope is that you always find what you came for and feel as inspired by our collections as we are.

    2026-06-03 07:49 UTC
  • web:playvalorant.com

    VALORANT Patch Notes 12.08 Introducing Skirmish: Ascension, new map rotation, and the return of Premier Game Updates 4/14/2026

    2026-06-03 07:49 UTC
  • web:www.dbtsupport.com

    Executive Summary The May 2026 Microsoft Patch Tuesday release includes security updates across supported Microsoft products and should be reviewed directly in the Microsoft Security Update Guide for the final CVE list, affected products, severity ratings, exploitability assessments, and any revised guidance. For enterprise IT teams, this month is especially important because the June 2026 ...

    2026-06-03 07:49 UTC
  • web:www.romhacking.net

    Add temporary header() Patch file: Apply patch Original ROM: Modified ROM: Patch type: IPS BPS PPF UPS APS RUP Create patch Settings Rom Patcher JS v2.9 by Marc Robledo See on GitHub Donate Language English Français Deutsch Italiano Español Nederlands Svenska Català Valencià Português Brasileiro Russian 日本語 中文(简体) 中文 ...

    2026-06-03 07:49 UTC
  • web:www.tomshardware.com

    Installing this month's Windows Server security update has knocked some enterprise domain controllers into continuous reboot cycles, Microsoft confirmed in a release health dashboard entry.

    2026-06-03 07:49 UTC
  • web:x.com

    Attention, Helldivers! Due to an unexpected submission bug outside of our control, today's patch will be slightly delayed. We're working to confirm an updated release time, but this depends on our platform partners, who are actively investigating and resolving the issue. We will share more information as soon as a new release time is confirmed. In the meantime, we are sharing the expanded ...

    2026-06-03 07:49 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2025-8903.json.

{
  "containers": {
    "cna": {
      "providerMetadata": {
        "dateUpdated": "2026-05-01T19:20:35.765Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "rejectedReasons": [
        {
          "lang": "en",
          "value": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-2052. Reason: This candidate is a reservation duplicate of CVE-2026-2052 Notes: All CVE users should reference CVE-2026-2052 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage."
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2025-8903",
    "dateRejected": "2026-05-01T19:20:35.765Z",
    "dateReserved": "2025-08-12T18:43:55.165Z",
    "dateUpdated": "2026-05-01T19:20:35.765Z",
    "state": "REJECTED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}