Fortinet, Ivanti, and SAP have released urgent security updates to address multiple critical vulnerabilities in their respective products, with potential impacts including authentication bypass, remote code execution, and stored cross-site scripting. Fortinet's advisories detail two flaws (CVE-2025-59718 and CVE-2025-59719, CVSS 9.8) in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, which could allow unauthenticated attackers to bypass FortiCloud SSO login authentication via crafted SAML messages if the feature is enabled. Ivanti has patched four vulnerabilities in Endpoint Manager, including a critical stored XSS flaw (CVE-2025-10573, CVSS 9.6) that could let remote attackers execute arbitrary JavaScript in administrator sessions. Organizations are advised to disable FortiCloud SSO login as a temporary mitigation and apply all available updates promptly.
SAP's December security updates address 14 vulnerabilities, including three critical flaws. The most severe, CVE-2025-42880 (CVSS 9.9), is a code injection vulnerability in SAP Solution Manager that could grant attackers full system control. Additional critical issues include CVE-2025-55754 (CVSS 9.6), affecting SAP Commerce Cloud due to Apache Tomcat vulnerabilities, and CVE-2025-42928 (CVSS 9.1), a deserialization flaw in SAP jConnect that could enable remote code execution. SAP's bulletin also includes fixes for several high- and medium-severity vulnerabilities across its product suite, underscoring the need for immediate patching to mitigate exploitation risks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security researchers from Rapid7, SOCRadar, and Onapsis were credited with the discovery and analysis of the SAP vulnerabilities addressed in the December updates. Their work helped identify risks including code injection, deserialization, and Apache Tomcat-related issues.
SAP issued its December 2025 security updates, fixing 14 vulnerabilities across multiple products. The release included three critical flaws: CVE-2025-42880 in Solution Manager, CVE-2025-55754 in Commerce Cloud, and CVE-2025-42928 in jConnect SDK.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.