CVE-2025-14543CRITICAL 9.1EPSS p10.5%

CVE-2025-14543CVE-2025-14543

Description

Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.21% probability of exploitation · percentile 10.5% · 2026-06-19T12:03:05Z
Published2026-04-30
Last modified2026-05-04

Underlying weaknesses· 1

CWE-611

References

  1. https://www.rti.com/vulnerabilities/#cve-2025-14543

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of XML External Entity Referencecwe-6110%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-4374
CVE
CVE-2025-4993
CVE
CVE-2025-1255
CVE
CVE-2026-8045
CVE
CVE-2024-5625
CVE
CVE-2025-42966
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.