Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet, Ivanti Patch High-Severity Vulnerabilities

Fortinet, Ivanti Patch High-Severity Vulnerabilities

Posted on June 11, 2025June 11, 2025 By CWS

Fortinet and Ivanti on Tuesday introduced fixes for over a dozen vulnerabilities throughout their product portfolios, together with a number of high-severity flaws.

Ivanti launched a Workspace Management (IWC) replace to handle three high-severity bugs that would result in credential leaks.

Tracked as CVE-2025-5353, CVE-2025-22463, and CVE-2025-22455, the problems exist due to hardcoded keys in IWC variations 10.19.0.0 and prior, which may enable authenticated attackers to decrypt saved SQL credentials and atmosphere passwords.

“We aren’t conscious of any prospects being exploited by these vulnerabilities previous to public disclosure. These vulnerabilities have been disclosed by way of our accountable disclosure program,” the corporate notes.

Fortinet launched 14 patches on Tuesday, to handle one high- and 13 medium-severity safety defects.

The high-severity problem, tracked as CVE-2025-31104, is described as an OS command injection bug in FortiADC that would enable an authenticated attacker to execute arbitrary code utilizing crafted HTTP requests.

The corporate mounted medium-severity flaws in FortiOS, FortiClientEMS, FortiClient for Home windows, FortiPAM, FortiSRA, FortiSASE, FortiPortal, FortiProxy, and FortiWeb.

Attackers may exploit these points to carry out SSRF assaults, inject unauthorized periods, redirect VPN connections, entry unauthorized assets, entry SSL-VPN settings, view system data, log into the SSL-VPN portal, elevate privileges, add SSH key recordsdata on the system, carry out operations on behalf of a focused person, spoof the id of a downstream system, and join from FortiClient by way of revoked certificates.Commercial. Scroll to proceed studying.

Fortinet makes no point out of any of those vulnerabilities being exploited within the wild. Further data will be discovered on the corporate’s PSIRT advisories web page.

Associated: Chrome, Firefox Updates Resolve Excessive-Severity Reminiscence Bugs

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Associated: Crucial Vulnerability Patched in SAP NetWeaver

Associated: Over 30 Vulnerabilities Patched in Android

Security Week News Tags:Fortinet, HighSeverity, Ivanti, Patch, Vulnerabilities

Post navigation

Previous Post: 40,000 Security Cameras Exposed to Remote Hacking
Next Post: Webinar Today: Rethinking Endpoint Hardening for Today’s Attack Landscape

Related Posts

Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US Security Week News
Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Security Week News
Critical Chrome Vulnerability Earns Researcher ,000 Critical Chrome Vulnerability Earns Researcher $43,000 Security Week News
GhostPoster Firefox Extensions Hide Malware in Icons GhostPoster Firefox Extensions Hide Malware in Icons Security Week News
New UK Framework Pressures Vendors on SBOMs, Patching and Default MFA New UK Framework Pressures Vendors on SBOMs, Patching and Default MFA Security Week News
Cisco Introduces Open Source AI Provenance Tool Cisco Introduces Open Source AI Provenance Tool Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Accuses OpenAI of Trade Secret Misappropriation
  • Espionage Campaigns Target Pakistani Police Portals
  • Compromised jscrambler npm Package Drops Infostealer
  • Ghostcommit Exploit Hides Malicious Code in Images
  • Ghost Accounts Exploit GitHub API in Major Reconnaissance Effort

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Accuses OpenAI of Trade Secret Misappropriation
  • Espionage Campaigns Target Pakistani Police Portals
  • Compromised jscrambler npm Package Drops Infostealer
  • Ghostcommit Exploit Hides Malicious Code in Images
  • Ghost Accounts Exploit GitHub API in Major Reconnaissance Effort

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark