Advisories

Critical 0-day Vulnerability in Citrix NetScaler Under Active Exploitation (CVE-2025-7775)

On August 26th, Citrix published an advisory detailing a critical vulnerability in their NetScaler line of products. Successful exploitation of this bug (tracked as CVE-2025-7775) grants an unauthenticated threat actor Remote Code Execution (RCE) on the device. These devices are typically deployed as internet facing by design, so this vulnerability can be used by threat actors to gain initial access to an organization’s internal network.

Aug 26, 2025 - 3 Min Read

Threat Actors Targeting Sonicwall Gen 7 and Newer Firewalls

On August 4th, SonicWall support published an advisory concerning an increase in threat activity targeting their Gen 7 Firewall product lineup, specifically with the SSLVPN component enabled.

Aug 5, 2025 - 7 Min Read

Critical Vulnerabilities in SonicWall SMA (CVE-2025-40596, CVE-2025-40597, CVE-2025-40598)

On July 23, 2025, SonicWall released three newly disclosed vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 100 series devices: CVE-2025-40596, CVE-2025-40597, and CVE-2025-40598. The vulnerabilities, if successfully exploited, range from allowing unauthenticated attackers to perform Denial of Service (DoS) attack to executing arbitrary JavaScript code. The vulnerabilities were found and reported to SonicWall by a third-party cyber security firm, and SonicWall quickly released patches through normal update channels. Additionally, SonicWall has not confirmed active exploitation of vulnerabilities at the time of this writing. However, the reporting security firm has published proof-of-concept details and technical walkthroughs, increasing likelihood of active exploitation.

Jul 29, 2025 - 4 Min Read

Critical Vulnerability In CrushFTP Under Active Exploitation (CVE-2025-54309)

On July 18, 2025, CrushFTP confirmed active exploitation of a zero-day vulnerability impacting its secure file transfer platform. Identified as CVE‑2025‑54309, the flaw allows remote attackers to bypass authentication mechanisms and gain unauthorized access to vulnerable servers.

Jul 22, 2025 - 5 Min Read

SharePoint 0Day Vulnerability Under Active Exploitation (CVE-2025-53770)

Microsoft's SharePoint on-premise servers are vulnerable to an unauthorized Remote Code Exploit that is being actively exploited. CVE-2025-53770 dubbed "Toolshell" was found in the wild July 18th 2025 and requires immediate mitigation for those running on-premise SharePoint Servers.

Jul 21, 2025 - 6 Min Read

Critical Vulnerabilities in Citrix Netscaler Services and "CitrixBleed 2" (CVE-2025-6543, CVE-2025-5777)

Cloud Software Group, the holding company of Citrix, recently disclosed multiple critical vulnerabilities affecting Citrix NetScaler ADC and Gateway products, with the most severe being CVE-2025-6543 and CVE-2025-5777. These vulnerabilities allow unauthenticated attackers to perform memory overflow attacks.

Jun 25, 2025 - 5 Min Read

Critical Vulnerability Microsoft Remote Desktop Gateway (CVE-2025-21297)

On January 12th, 2025, Microsoft published an advisory regarding a critical vulnerability in their Remote Desktop Services product. The vulnerability is due to a race condition that can lead to memory corruption. If successfully exploited, an attacker can achieve remote code execution (RCE) on a victim server.

May 21, 2025 - 3 Min Read

Critical Vulnerabilities in SAP NetWeaver Visual Composer (CVE-2025-31324, CVE-2025-42999)

On April 24, 2025, software company SAP published an advisory regarding a critical vulnerability embedded within a component of their NetWeaver product (CVE-2025-31324). On May 15, 2025, CISA added a related, critical SAP NetWeaver deserialization vulnerability (CVE-2025-42999) to its KEV list.

May 20, 2025 - 4 Min Read

Critical Vulnerabilities in multiple Fortinet devices under Active Exploitation (CVE-2025-32756)

On May 13th, Fortinet published an advisory regarding a critical buffer overflow vulnerability identified as CVE-2025-32756 affecting FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera devices. If exploited successfully, the vulnerability could allow unauthenticated attackers to execute arbitrary code or commands via malicious HTTP cookies.

May 15, 2025 - 6 Min Read

Critical Vulnerability Updates in SonicWall (CVE-2023-44221, CVE-2024-38475)

On May 1st, watchTowr Labs published an article detailing new information on two previously reported critical vulnerabilities in SonicWall SMA: CVE-2024-38475 and CVE-2023-44221. These vulnerabilities are an arbitrary file read and a command injection, and successful combined exploitation of them would grant a threat actor remote code execution (RCE) on a target device. Both vulnerabilities were added to the CISA KEV on the same day, and Beazley Security is aware of active “In the Wild” exploitation of these vulnerabilities.

May 1, 2025 - 10 Min Read