ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security-Affairs-Newsletter-Round-555-By-Pierluigi-Paganini-International

criticalRansomware exploited in the wildimportance 60CVE-2025-59718CVE-2025-59719CVE-2025-40602

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-40602
Missing Authorization Flaw in SonicWall SMA1000 Appliance Management Console

CVE-2025-40602 is a missing-authorization vulnerability (CWE-862, with CWE-250 unnecessary-privilege issues) in the appliance management console (AMC) of SonicWall's SMA1000 secure-access appliances, characterized by CISA as a privilege escalation flaw; the CVSS vector (AV:N/AC:H/PR:H/UI:N, CVSS 3.1 score 6.6) indicates it is reachable over the network but requires an attacker that already holds high privileges. An attacker who has obtained AMC access can invoke insufficiently authorized actions to escalate privileges and gain high-impact control of the appliance, with high confidentiality, integrity, and availability impact. Affected products are the SMA1000 appliance line — SMA 6200, 6210, 7200, and 7210 firmware and the SMA 8200V virtual appliance. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-17 and SonicWall has warned of active exploitation and shipped fixes, while EPSS estimates a 2.1% probability of exploitation within 30 days (81st percentile) and ransomware use is unknown.

Do: Apply the patched SMA1000 firmware identified in SonicWall's security advisory immediately (the source data does not specify the fixed version), and follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable. Until patched, restrict AMC access to trusted management networks or a VPN, and review appliance logs for indicators of unauthorized access since exploitation is confirmed in the wild.

6.62% KEV
  • SonicWall SMA1000 appliance - SMA 6200 firmware
  • SonicWall SMA1000 appliance - SMA 6210 firmware
  • SonicWall SMA1000 appliance - SMA 7200 firmware
  • +2 more
large≈10,000–100,000 SMA1000 appliances/management consoles deployed (exact internet-exposed count unknown)
CVE-2025-59718
Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy

CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days.

Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01.

9.868% KEV
  • Fortinet FortiOS 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3
  • Fortinet FortiProxy 7.0.0-7.0.21, 7.2.0-7.2.14, 7.4.0-7.4.10, 7.6.0-7.6.3
  • Fortinet FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6
  • +1 more
masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the…
CVE-2025-59719
Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO)

FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible.

Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent.

9.829%
  • fortinet fortiweb 8.0.0
  • fortinet fortiweb 7.6.0 through 7.6.4
  • fortinet fortiweb 7.4.0 through 7.4.9
largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud…
Full article482 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 21, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Data breach at credit check giant 700Credit affects at least 5.6 million

Beware: PayPal subscriptions abused to send fake purchase emails

PornHub extorted after hackers steal Premium member activity data  

Man jailed for teaching criminals how to use malware      

GuardDuty Extended Threat Detection uncovers cryptomining campaign on Amazon EC2 and Amazon ECS  

700,000 Records Compromised in Askul Ransomware Attack  

Fraudulent call centres in Ukraine rolled up  

Most Parked Domains Now Serving Malicious Content  

DIG AI: Uncensored Darknet AI Assistant at the Service of Criminals and Terrorists  

Clop ransomware targets Gladinet CentreStack in data theft attacks  

Tren De Aragua Members and Leaders Indicted in Multi-Million Dollar ATM Jackpotting Scheme  

Nigeria arrests suspected RaccoonO365 phishing kit developer on tip from Microsoft, FBI  

Malware

CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks

About ZnDoor, a malware executed by React2Shell  

Malicious NuGet Package Typosquats Popular .NET Tracing Library to Steal Wallet Passwords   

Meet Cellik – A New Android RAT With Play Store Integration  

Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices  

Hacking

Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719  

Exploitation of Critical Vulnerability in React Server Components (Updated December 12)  

GhostPairing Attacks: from phone number to full access in WhatsApp  

SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

Vulnerability in UEFI firmware modules prevents IOMMU initialization on some UEFI-based motherboards  

Intelligence and Information Warfare

“An attacker was able to access a number of files”: on RTL, Laurent Nuñez confirmed “a cyberattack” at the Ministry of the Interior  

Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure  

Italian ship stopped in France: had malware on board. Latvian sailor accused of espionage  

Cisco says Chinese hackers are exploiting its customers with a new zero-day

UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager  

Denmark says Russia was behind two ‘destructive and disruptive’ cyber-attacks 

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

Cybersecurity

MOBILE PHONES THREAT LANDSCAPE SINCE 2015

‘Completely Deactivate Wi-Fi’—Cyber Agency Warns iPhone And Android Users     

Venezuela’s PDVSA suffers cyberattack, tankers make u-turns amid tensions with US  

Learn about updates to dark web report  

Texas sues TV makers for taking screenshots of what people watch

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Dismantling Defenses: Trump 2.0 Cyber Year in Review

Hacks, thefts, and disruption: The worst data breaches of 2025  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185930/breaking-news/security-affairs-newsletter-round-555-by-pierluigi-paganini-international-edition.html