CVE-2025-10492: exploitation status and patch state
CVE-2025-10492 · CVSS 9.8 CRITICAL · EPSS 1%
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
Is CVE-2025-10492 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.