Security-Affairs-Newsletter-Round-555-By-Pierluigi-Paganini-International
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-40602 | Missing Authorization Flaw in SonicWall SMA1000 Appliance Management Console CVE-2025-40602 is a missing-authorization vulnerability (CWE-862, with CWE-250 unnecessary-privilege issues) in the appliance management console (AMC) of SonicWall's SMA1000 secure-access appliances, characterized by CISA as a privilege escalation flaw; the CVSS vector (AV:N/AC:H/PR:H/UI:N, CVSS 3.1 score 6.6) indicates it is reachable over the network but requires an attacker that already holds high privileges. An attacker who has obtained AMC access can invoke insufficiently authorized actions to escalate privileges and gain high-impact control of the appliance, with high confidentiality, integrity, and availability impact. Affected products are the SMA1000 appliance line — SMA 6200, 6210, 7200, and 7210 firmware and the SMA 8200V virtual appliance. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-17 and SonicWall has warned of active exploitation and shipped fixes, while EPSS estimates a 2.1% probability of exploitation within 30 days (81st percentile) and ransomware use is unknown. Do: Apply the patched SMA1000 firmware identified in SonicWall's security advisory immediately (the source data does not specify the fixed version), and follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable. Until patched, restrict AMC access to trusted management networks or a VPN, and review appliance logs for indicators of unauthorized access since exploitation is confirmed in the wild. | 6.6 | 2% | KEV |
| large≈10,000–100,000 SMA1000 appliances/management consoles deployed (exact internet-exposed count unknown) | |
| CVE-2025-59718 | Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days. Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01. | 9.8 | 68% | KEV |
| masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the… | |
| CVE-2025-59719 | Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO) FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible. Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent. | 9.8 | 29% |
| largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud… |
Full article482 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 21, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Data breach at credit check giant 700Credit affects at least 5.6 million
Beware: PayPal subscriptions abused to send fake purchase emails
PornHub extorted after hackers steal Premium member activity data
Man jailed for teaching criminals how to use malware
GuardDuty Extended Threat Detection uncovers cryptomining campaign on Amazon EC2 and Amazon ECS
700,000 Records Compromised in Askul Ransomware Attack
Fraudulent call centres in Ukraine rolled up
Most Parked Domains Now Serving Malicious Content
DIG AI: Uncensored Darknet AI Assistant at the Service of Criminals and Terrorists
Clop ransomware targets Gladinet CentreStack in data theft attacks
Tren De Aragua Members and Leaders Indicted in Multi-Million Dollar ATM Jackpotting Scheme
Nigeria arrests suspected RaccoonO365 phishing kit developer on tip from Microsoft, FBI
Malware
CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks
About ZnDoor, a malware executed by React2Shell
Malicious NuGet Package Typosquats Popular .NET Tracing Library to Steal Wallet Passwords
Meet Cellik – A New Android RAT With Play Store Integration
Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices
Hacking
Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
GhostPairing Attacks: from phone number to full access in WhatsApp
SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
Vulnerability in UEFI firmware modules prevents IOMMU initialization on some UEFI-based motherboards
Intelligence and Information Warfare
Italian ship stopped in France: had malware on board. Latvian sailor accused of espionage
Cisco says Chinese hackers are exploiting its customers with a new zero-day
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
Denmark says Russia was behind two ‘destructive and disruptive’ cyber-attacks
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
Cybersecurity
MOBILE PHONES THREAT LANDSCAPE SINCE 2015
‘Completely Deactivate Wi-Fi’—Cyber Agency Warns iPhone And Android Users
Venezuela’s PDVSA suffers cyberattack, tankers make u-turns amid tensions with US
Learn about updates to dark web report
Texas sues TV makers for taking screenshots of what people watch
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Dismantling Defenses: Trump 2.0 Cyber Year in Review
Hacks, thefts, and disruption: The worst data breaches of 2025
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185930/breaking-news/security-affairs-newsletter-round-555-by-pierluigi-paganini-international-edition.html