Fortinet , Ivanti , and SAP have moved to address critical security vulnerabilities in their products that, if successfully exploited, could lead to authentication bypass and code execution .

Fortinet vulnerabilities
The Fortinet vulnerabilities affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and are related to an incorrect cryptographic signature verification case. They are documented as CVE-2025-59718 and CVE-2025-59719 (CVSS scores: 9.8).
“A cryptographic signature verification flaw [CWE-347] in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager could allow an unauthenticated attacker to bypass authentication via a crafted SAML message (if this feature is enabled on the device),” said in an advisory.
See also: Emby Server: Critical vulnerability allows administrator access
The company noted that the FortiCloud SSO login feature is not enabled in the factory default settings. FortiCloud SSO login is enabled when an administrator enrolls the device in FortiCare and has not disabled the “Allow administrative login using FortiCloud SSO” option on the enrollment page.
To temporarily protect their systems from attacks that exploit these vulnerabilities, organizations are advised to disable the FortiCloud connectivity feature (if enabled). This can be done in two ways:
1. Go to System -> Settings -> Change “Allow administrative login using FortiCloud SSO” to OFF.
2. Execute the command in the CLI –
config system global set admin-forticloud-sso-login disable end
Ivanti Vulnerabilities
Ivanti has also issued updates to address four security vulnerabilities in Endpoint Manager (EPM). One of them is a critical error in the EPM kernel and remote consoles. The vulnerability, tracked as CVE-2025-10573, has a CVSS score of 9.6.
“ Stored XSS in Ivanti Endpoint Manager before version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session ,” Ivanti said
See also: Exploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT
Rapid7 security researcher Ryan Emmons, who discovered and reported the vulnerability on August 15, 2025, said it allows an attacker to gain access to the core EPM web service and add fake managed endpoints to the EPM server to infect the administrator's dashboard with malicious JavaScript.
“ When an Ivanti EPM administrator views one of the infected dashboard interfaces during normal use, this passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator’s session ,” Emmons said
The company noted that user interaction to exploit the vulnerability and that it is not aware of any ongoing attacks. It has been fixed in EPM version 2024 SU4 SR1.
Also fixed in the same release are three other high severity vulnerabilities (CVE-2025-13659, CVE-2025-13661 and CVE-2025-13662) that could allow a remote, unauthenticated attacker to achieve arbitrary code execution. CVE-2025-13662 stems from incorrect verification of cryptographic signatures in the patch management component.

SAP vulnerabilities
Finally, SAP has issued December security updates to address 14 vulnerabilities across multiple products, including three critical vulnerabilities:
– CVE-2025-42880 (CVSS score: 9.9) – A code injection vulnerability in SAP Solution Manager.
– CVE-2025-55754 (CVSS score: 9.6) – Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud.
– CVE-2025-42928 (CVSS score: 9.1) – A deserialization vulnerability in the SAP jConnect SDK for Sybase Adaptive Server Enterprise (ASE).
SAP's Boston-based security platform, Onapsis, has been identified for reporting CVE-2025-42880 and CVE-2025-42928. The company said it identified a remote-enabled function module in SAP Solution Manager that could allow an authorized attacker to inject arbitrary code.
See also: Apache Tika: Risk from vulnerability that was fixed months ago
"Given the central role of SAP Solution Manager in the SAP systems landscape, we strongly recommend a timely patch," said Onapsis security researcher Thomas Fritsch.
On the other hand, CVE-2025-42928 allows remote code execution by providing specially crafted input to the SAP jConnect SDK component. However, a successful exploitation requires elevated privileges.
Vulnerabilities in software from Fortinet, Ivanti, and SAP show that it is essential for users to move quickly to apply fixes.
