CVE-2025-35433: exploitation status and patch state
CVE-2025-35433 · CVSS 5.0 MEDIUM · EPSS <1%
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
Is CVE-2025-35433 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.