Critical Security Flaws Found in Fortinet, Ivanti, and SAP Products: Urgent Patches Released

Listen to this Post

Featured Image
In a troubling wave of cybersecurity alerts, Fortinet, Ivanti, and SAP have all disclosed critical security vulnerabilities in their products that could allow attackers to bypass authentication mechanisms or execute arbitrary code remotely. These flaws, rated with extremely high severity scores, emphasize the urgent need for organizations and system administrators to implement security patches immediately to prevent potential breaches.

Fortinet Vulnerabilities: Cryptographic Signature Flaw Risks Authentication Bypass

Fortinet disclosed severe vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, linked to improper verification of cryptographic signatures (CVE-2025-59718 and CVE-2025-59719, CVSS 9.8). These flaws could allow unauthenticated attackers to bypass FortiCloud SSO login via crafted SAML messages—but only if the feature is enabled. Fortinet noted that this feature is not active by default; it is only enabled when administrators register the device to FortiCare and leave the “Allow administrative login using FortiCloud SSO” toggle on.

As a temporary mitigation, administrators are advised to disable FortiCloud SSO login until patches are applied. This can be done either via the system settings interface or by running a CLI command to disable the login feature.

Ivanti Endpoint Manager Flaw: Critical XSS and Code Execution Risks

Ivanti has patched four security flaws in Endpoint Manager (EPM), including a critical stored XSS vulnerability (CVE-2025-10573, CVSS 9.6). The flaw allows unauthenticated attackers to inject malicious JavaScript into the administrator dashboard, potentially compromising sessions when an admin views the poisoned interface.

Researcher Ryan Emmons, who reported the issue, explained that attackers could register fake endpoints to the EPM server, triggering JavaScript execution in the admin’s session. Although user interaction is required to exploit the flaw, Ivanti emphasized that immediate patching is critical.

Three additional high-severity vulnerabilities (CVE-2025-13659, CVE-2025-13661, and CVE-2025-13662) were patched in the same update. CVE-2025-13662 also involves improper cryptographic signature verification, mirroring similar issues found in Fortinet products.

SAP Updates: Critical Fixes for Solution Manager, Commerce Cloud, and jConnect SDK

SAP released December security updates addressing 14 vulnerabilities across multiple products, including three critical flaws:

CVE-2025-42880 (CVSS 9.9): Code injection vulnerability in SAP Solution Manager

CVE-2025-55754 (CVSS 9.6): Multiple flaws in Apache Tomcat within SAP Commerce Cloud

CVE-2025-42928 (CVSS 9.1): Deserialization vulnerability in SAP jConnect SDK for Sybase ASE

Onapsis, the security platform that reported two of these vulnerabilities, highlighted that the Solution Manager flaw allows authenticated attackers to inject arbitrary code, which could have devastating effects due to Solution Manager’s central role in SAP environments. The jConnect SDK vulnerability also enables remote code execution but requires elevated privileges.

What Undercode Say:

The recent disclosures across Fortinet, Ivanti, and SAP reveal a concerning pattern in enterprise software security: improper cryptographic signature verification and insufficient authentication safeguards are recurring high-risk vulnerabilities. While Fortinet and Ivanti demonstrate different exploitation paths—SSO bypass versus stored XSS attacks—the root cause is a lack of robust validation mechanisms. These flaws underscore the ongoing challenge for vendors to balance functionality with security, especially in complex enterprise environments where default configurations may unintentionally expose attack surfaces.

From a broader perspective, the high CVSS scores (9.1–9.9) signal that these vulnerabilities are extremely likely to be targeted by attackers, particularly in automated attacks or phishing campaigns exploiting administrative privileges. The fact that some flaws require no authentication, like Fortinet’s CVE-2025-59718, makes them highly attractive for threat actors. Organizations that delay patching risk credential theft, unauthorized system control, or complete compromise of critical infrastructure.

Ivanti’s stored XSS vulnerability illustrates the subtle but dangerous impact of client-side attacks. Even though exploitation requires user interaction, the ability to hijack an admin session demonstrates how seemingly minor flaws can escalate to severe breaches. Similarly, SAP’s Solution Manager code injection and jConnect SDK deserialization flaws highlight the criticality of patching in large-scale enterprise systems where centralized tools manage complex workflows.

Another key takeaway is the role of responsible disclosure and the security research community. Rapid7 and Onapsis both played pivotal roles in identifying and reporting these vulnerabilities, showcasing the importance of collaboration between vendors and external researchers to protect global digital ecosystems.

The recurrence of cryptographic signature issues across vendors also suggests a need for more rigorous code audits, automated cryptography checks, and perhaps even formal verification of critical security components. For enterprises, adopting a proactive patch management strategy, conducting penetration testing, and auditing default configurations could reduce exposure to these types of vulnerabilities.

Finally, the alignment between multiple high-risk disclosures in December indicates a potential surge in threat activity. Security teams should anticipate opportunistic attacks targeting unpatched systems, particularly those using default configurations or poorly monitored SSO services. This is a critical reminder that even well-established vendors with extensive security programs are not immune to high-impact vulnerabilities.

Fact Checker Results:

✅ Fortinet, Ivanti, and SAP have all released patches addressing critical flaws.
❌ Exploitation in the wild has not been confirmed for Ivanti’s stored XSS vulnerability.
✅ CVSS scores indicate these vulnerabilities are high-risk and require immediate action.

Prediction:

With attackers continuously scanning for enterprise misconfigurations, the Fortinet SSO and Ivanti EPM vulnerabilities are likely to become prime targets in the coming months. SAP’s Solution Manager flaw could attract attention from threat groups seeking high-value enterprise compromise. Organizations that delay patching may face targeted ransomware campaigns or administrative account takeovers, while proactive patching will dramatically reduce their risk exposure. 🔒

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon