ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

New Fortinet and Ivanti Zero Days Exploited in the Wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-32756CVE-2025-4427CVE-2025-4428

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-32756
Stack-based overflow RCE in Fortinet FortiMail, FortiVoice, FortiNDR, FortiFone

CVE-2025-32756 is a stack-based buffer overflow (CWE-124) in Fortinet's FortiMail, FortiVoice, FortiNDR and FortiFone products that is reachable over the network and requires no authentication. An attacker triggers the flaw by sending crafted HTTP requests to the affected device's web-facing service. Successful exploitation yields arbitrary code or command execution on the appliance, giving the attacker control of the device and any traffic or data it handles (such as email or voice services). Organizations running these Fortinet appliances or phones are affected, particularly where the devices are reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-14, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is unconfirmed, and EPSS puts its 30-day exploitation probability at about 30% (98th percentile).

Do: Inventory your environment for FortiMail, FortiVoice, FortiNDR and FortiFone deployments and apply the patched releases specified in Fortinet's advisory for CVE-2025-32756. Until patched, restrict internet exposure of the affected devices' HTTP/HTTPS interfaces (limit admin and web access to trusted networks/VPN) per vendor mitigation guidance, and review device logs for signs of exploitation. Federal agencies must apply the required mitigations or discontinue use per BOD 22-01 deadlines.

9.830% KEV
  • Fortinet FortiMail
  • Fortinet FortiVoice
  • Fortinet FortiNDR
  • +1 more
largeLikely on the order of tens of thousands of deployed appliances/phones (estimate)
CVE-2025-4428
+1 in the same advisory: …4427
Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API

CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed.

Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated.

8.8
group max
86% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior (API component; affected platforms unspecified in the source data)
largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed)
Full article624 words · extracted from infosecurity-magazine.com · click to collapse

Fortinet and Ivanti have warned customers that attackers are exploiting new zero day vulnerabilities affecting a range of products.

The tech firms published separate advisories on the flaws, one of which is critical, on May 13, urging customers to apply fixes as soon as possible.

Cybersecurity vendor Fortinet provided details on a stack-based overflow vulnerability, CVE-2025-32756. An exploit can enable a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

The flaw has been given a critical CVSS score of 9.6.

The vulnerability impacts the following Fortinet products: FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera.

The firm said that flaw has been observed being exploited in the wild on FortiVoice.

In the case observed by Fortinet, the threat actor was able to perform a range of operations on the victim device:

  • Scan the device network
  • Erase system crashlogs
  • Enable fcgi debugging to log credentials from the system or SSH login attempts

No information has been given on the identity of the threat actor.

Fortinet also provided an indicator of compromise (IOC) list, including logs and IP addresses, to help customers check for signs of exploitation.

To check if fcgi debugging is enabled on their system, customers should use the CLI command: diag debug application fcgi.

If the output shows “general to-file ENABLED”, it means fcgi debugging is enabled.

Fortinet has released a patch for the vulnerability, and customers are urged to upgrade their tools to apply the fix.

Organizations can also disable the HTTP/HTTPS administrative interface as a temporary workaround.

Read now: Fortinet Confirms Critical Zero-Day Vulnerability in Firewalls

Ivanti Discloses Open Source Vulnerabilities

Ivanti provided details of two newly discovered vulnerabilities affecting its products, one medium (CVE-2025-4427) and one high severity (CVE-2025-4428).

They both impact Ivanti Endpoint Manager and two open-source libraries integrated into the product.

Ivanti said it is working with maintainers of the libraries to determine if a CVE against the libraries is warranted for the benefit of the broader security ecosystem. 

The IT software provider warned that when chained together, successful exploitation could lead to unauthenticated remote code execution.

“We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure,” the company wrote.

Customers should install a fixed version of the product as soon as possible.

There are some workarounds available to reduce the risk of compromise, including filtering access to the API using either the built in Portal ACLs functionality or an external WAF.

Vendors Must Be Held Accountable for “Unforgivable” Vulnerabilities

During a talk at the CYBERUK 2025 conference in May, National Cyber Security Centre (NCSC) CTO Ollie Whitehouse discussed the urgent need for software vendors to be held to account for major security flaws impacting their products.

He argued that the technology market does not currently reward companies that put significant resources into building secure products by design.

“Edge network devices and security devices continue to have a plethora of unforgivable vulnerabilities in them,” Whitehouse commented.

“If even the products that are meant to help us and save us have unforgiveable classes of vulnerabilities, how can we expect a different outcome?” he added.

Read now: Learning from 2024: An Unprecedented Exploitation of Remote Access Technologies

The UK government is taking steps to create market incentives for stronger security in these products, including the growing use of guidelines to stimulate more understanding among consumers.

During CYBERUK, the government unveiled two new cybersecurity assessment schemes to enable firms to demonstrate their cyber resiliency, and boost confidence in the products and services used by organizations.

One of these, the Cyber Resilience Test Facilities (CTFR) program, will develop a network of assured facilities that can independently audit the cybersecurity of technology vendors’ products in a consistent and structured way.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/fortinet-ivanti-zero-days/