BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fortinet, Ivanti, SAP Release Critical Security Patches Dec 2025

Fortinet, Ivanti, and SAP Patch Critical Vulnerabilities in December 2025 Security Updates

  • Fortinet fixed critical vulnerabilities in FortiOS and related products involving improper cryptographic signature verification.
  • Ivanti released patches for Endpoint Manager, including a high-severity stored cross-site scripting flaw.
  • SAP addressed 14 vulnerabilities, with three rated critical for code injection, Apache Tomcat, and deserialization issues.
  • Users are advised to update affected products promptly and disable vulnerable features as temporary protection.

Fortinet, Ivanti, and SAP issued security updates in December 2025 to fix critical vulnerabilities that could allow attackers to bypass authentication or execute code. These flaws affect various products including Fortinet’s FortiOS and FortiCloud SSO login, Ivanti’s Endpoint Manager, and multiple SAP solutions.

- Advertisement -

The flaws in Fortinet products, tracked as CVE-2025-59718 and CVE-2025-59719 with CVSS scores of 9.8, involve improper verification of cryptographic signatures. This can allow an attacker to bypass FortiCloud single sign-on authentication by sending a crafted SAML message, if the feature is enabled. Fortinet warned that FortiCloud SSO is not enabled by default but can be disabled temporarily via system settings or CLI commands as described in their advisory at Fortinet’s security advisory.

Ivanti addressed four flaws in Endpoint Manager, including a critical stored cross-site scripting (XSS) vulnerability, CVE-2025-10573, scored 9.6. This flaw allows unauthenticated attackers to inject malicious JavaScript into the administrator’s dashboard by joining fake managed endpoints to the server. The issue, discovered by Rapid7 researcher Ryan Emmons, requires an administrator’s passive interaction to trigger code execution. Ivanti confirmed no known active exploitation and patched the issue in Endpoint Manager version 2024 SU4 SR1. Additional high-severity vulnerabilities patched include CVE-2025-13659, CVE-2025-13661, and CVE-2025-13662, the last also related to improper cryptographic signature verification. Details are available in Ivanti’s update note at Ivanti’s security advisory.

SAP released updates for 14 vulnerabilities, including three critical bugs: CVE-2025-42880 (CVSS 9.9), a code injection flaw in SAP Solution Manager; CVE-2025-55754 (CVSS 9.6), multiple issues in Apache Tomcat within SAP Commerce Cloud; and CVE-2025-42928 (CVSS 9.1), a deserialization vulnerability in SAP jConnect SDK for Sybase Adaptive Server Enterprise. The first and third were reported by SAP security firm Onapsis, which emphasized the urgency of patching SAP Solution Manager due to its central role. Exploiting the jConnect SDK flaw requires elevated privileges. SAP’s full update details can be found at their official page SAP December security notes.

Organizations using these products should promptly apply updates and disable vulnerable features as interim safeguards to prevent exploitation.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

PayPal Joins Meta’s Muse AI Commerce Ecosystem

Paypal partnered with Meta to bring PayPal checkout to the Muse AI agent, enabling...

US Probes Binance Over Iran Sanctions Violations

The Manhattan US attorney's office and the Justice Department are investigating Binance over potential...

EU central banks drop stablecoin deposit rule for liquidity

The European System of Central Banks (ESCB) proposes replacing mandatory bank-deposit thresholds for stablecoin...

Critical VeloCloud Orchestrator flaw actively exploited

Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as...

Tigress Financial Hikes Google Stock Target to $485

Google stock (NASDAQ: GOOG) opened at $350 Tuesday after a 2.3% rise from $340...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading