This week, key vulnerabilities in SAP, Microsoft, Fortinet, Ivanti, and others demand immediate attention as threat actors exploit critical flaws.
Key vulnerabilities in SAP, Microsoft, Fortinet, and others demand immediate attention as threat actors exploit critical flaws.
Cyble Research and Intelligence Labs (CRIL) analyzed significant IT vulnerabilities disclosed between January 8 and 14, 2025.
The Cybersecurity and Infrastructure Security Agency (CISA) added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Microsoft released its January 2025 Patch Tuesday updates, addressing 159 vulnerabilities, including eight zero-days, three of which are under active exploitation.
Other notable vulnerabilities this week are flaws in SAP NetWeaver Application Server and other high-profile products. CRIL’s monitoring of underground forums also revealed discussions on critical zero-day vulnerabilities and their potential weaponization.
Impact: SAP NetWeaver’s foundational role in critical industries like finance, healthcare, and manufacturing makes these vulnerabilities particularly concerning.
Mitigation: Patches are available for all vulnerabilities, and immediate application is recommended.
Impact: Exploited in the wild, this vulnerability has been observed in attempts to gain super-admin privileges on affected systems.
Mitigation: Upgrade FortiOS to the latest patched versions (7.0.17 or above for version 7.0 and 7.2.13 or above for version 7.2).
Also read: Fortinet’s Authentication Bypass Zero-Day: Mitigation Strategies and IoCs for Enhanced Security
Impact: These vulnerabilities pose risks of denial-of-service or privilege escalation within virtualized environments.
Mitigation: Apply Microsoft’s January Patch Tuesday updates.
CRIL observed active discussions and Proof-of-Concept (PoC) code for vulnerabilities on underground forums:
Observed Activity: PoC shared on Telegram by a threat actor.
Observed Activity: Threat actor “dragonov_66” posted PoC on cybercrime forums.
Additionally, a threat actor advertised for sale zero-day pre-authentication Remote Code Execution (RCE) vulnerabilities affecting GoCloud Routers and Entrolink PPX VPN services.
The following vulnerabilities were added to CISA’s KEV catalog:
CVE ID | Vendor | Product | CVSSv3 | Exploitation |
CVE-2025-21335 | Microsoft | Windows | 7.8 | Not observed |
CVE-2024-55591 | Fortinet | FortiOS | 9.8 | Observed |
CVE-2023-48365 | Qlik | Sense | 9.8 | Observed |
CVE-2025-0282 | Ivanti | Connect Secure | 9.0 | Observed |
Also read: Inside the Active Threats of Ivanti’s Exploited Vulnerabilities
To mitigate risks associated with the identified vulnerabilities: