Critical Authentication and Code Execution Flaws Patched in Fortinet, Ivanti, and SAP Products
Summary
Hide ▲
Show ▼
Fortinet, Ivanti, and SAP have released urgent patches for critical vulnerabilities in their products. Fortinet addressed flaws in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow unauthenticated attackers to bypass authentication via crafted SAML messages. Ivanti patched a critical stored XSS flaw in Endpoint Manager (EPM) that could lead to arbitrary JavaScript execution. SAP fixed three critical vulnerabilities, including a code injection flaw in SAP Solution Manager and a deserialization vulnerability in SAP jConnect SDK.
Timeline
-
10.12.2025 06:50 1 articles · 6h ago
Critical Vulnerabilities Patched in Fortinet, Ivanti, and SAP Products
Fortinet, Ivanti, and SAP have released patches for critical vulnerabilities in their products. Fortinet addressed flaws in multiple products that could allow authentication bypass. Ivanti patched a critical stored XSS flaw in Endpoint Manager. SAP fixed three critical vulnerabilities, including a code injection flaw in SAP Solution Manager and a deserialization vulnerability in SAP jConnect SDK.
Show sources
- Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws — thehackernews.com — 10.12.2025 06:50
Information Snippets
-
Fortinet vulnerabilities (CVE-2025-59718, CVE-2025-59719) affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, allowing authentication bypass via improper cryptographic signature verification.
First reported: 10.12.2025 06:501 source, 1 articleShow sources
- Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws — thehackernews.com — 10.12.2025 06:50
-
Ivanti patched a critical stored XSS flaw (CVE-2025-10573) in Endpoint Manager, allowing remote unauthenticated attackers to execute arbitrary JavaScript in administrator sessions.
First reported: 10.12.2025 06:501 source, 1 articleShow sources
- Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws — thehackernews.com — 10.12.2025 06:50
-
SAP addressed three critical vulnerabilities, including CVE-2025-42880 (code injection in SAP Solution Manager) and CVE-2025-42928 (deserialization flaw in SAP jConnect SDK).
First reported: 10.12.2025 06:501 source, 1 articleShow sources
- Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws — thehackernews.com — 10.12.2025 06:50