BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fortinet, Ivanti, SAP Release Critical Security Patches Dec 2025

Fortinet, Ivanti, and SAP Patch Critical Vulnerabilities in December 2025 Security Updates

  • Fortinet fixed critical vulnerabilities in FortiOS and related products involving improper cryptographic signature verification.
  • Ivanti released patches for Endpoint Manager, including a high-severity stored cross-site scripting flaw.
  • SAP addressed 14 vulnerabilities, with three rated critical for code injection, Apache Tomcat, and deserialization issues.
  • Users are advised to update affected products promptly and disable vulnerable features as temporary protection.

Fortinet, Ivanti, and SAP issued security updates in December 2025 to fix critical vulnerabilities that could allow attackers to bypass authentication or execute code. These flaws affect various products including Fortinet’s FortiOS and FortiCloud SSO login, Ivanti’s Endpoint Manager, and multiple SAP solutions.

- Advertisement -

The flaws in Fortinet products, tracked as CVE-2025-59718 and CVE-2025-59719 with CVSS scores of 9.8, involve improper verification of cryptographic signatures. This can allow an attacker to bypass FortiCloud single sign-on authentication by sending a crafted SAML message, if the feature is enabled. Fortinet warned that FortiCloud SSO is not enabled by default but can be disabled temporarily via system settings or CLI commands as described in their advisory at Fortinet’s security advisory.

Ivanti addressed four flaws in Endpoint Manager, including a critical stored cross-site scripting (XSS) vulnerability, CVE-2025-10573, scored 9.6. This flaw allows unauthenticated attackers to inject malicious JavaScript into the administrator’s dashboard by joining fake managed endpoints to the server. The issue, discovered by Rapid7 researcher Ryan Emmons, requires an administrator’s passive interaction to trigger code execution. Ivanti confirmed no known active exploitation and patched the issue in Endpoint Manager version 2024 SU4 SR1. Additional high-severity vulnerabilities patched include CVE-2025-13659, CVE-2025-13661, and CVE-2025-13662, the last also related to improper cryptographic signature verification. Details are available in Ivanti’s update note at Ivanti’s security advisory.

SAP released updates for 14 vulnerabilities, including three critical bugs: CVE-2025-42880 (CVSS 9.9), a code injection flaw in SAP Solution Manager; CVE-2025-55754 (CVSS 9.6), multiple issues in Apache Tomcat within SAP Commerce Cloud; and CVE-2025-42928 (CVSS 9.1), a deserialization vulnerability in SAP jConnect SDK for Sybase Adaptive Server Enterprise. The first and third were reported by SAP security firm Onapsis, which emphasized the urgency of patching SAP Solution Manager due to its central role. Exploiting the jConnect SDK flaw requires elevated privileges. SAP’s full update details can be found at their official page SAP December security notes.

Organizations using these products should promptly apply updates and disable vulnerable features as interim safeguards to prevent exploitation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Kiyosaki: 1974’s economic shift fuels debt, retirement crisis

Robert Kiyosaki warns the financial changes initiated in 1974 are now creating inflation and...

Dogecoin (DOGE) Post a Notable Rebound, Experts Show More Interest In Taurox (TAUX) as It Opens Pre-KYA Registration

DOGE trades near $0.09 after a notable rebound. The official account’s April Fools’ corporate...

Conservatism Urged for Bitcoin Node Software

A new non-profit, ProductionReady, aims to fund a "conservative" Bitcoin node client to prioritize...

Anthropic Finds “Emotion Vectors” Inside Claude 4.5 AI

Anthropic researchers found internal "emotion vectors" in Claude Sonnet 4.5 that influence its decision-making.Increasing...

Dorsey’s Block Launches Bitcoin Faucet for Free Distributions

Block, led by Jack Dorsey, will revive the historic Bitcoin ‘faucet’ distribution model starting...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading