Fortra® Security & Trust Center
Emerging Threats
Fortra’s emerging threats process is initiated when we identify new or evolving risks to computer systems or networks. We manage emerging threats proactively by gathering threat intelligence and performing analysis that informs detection, mitigation, and protection strategies. While every threat is important for security teams to be aware of, the goal of emerging threat notifications is to call attention to the issues that represent the most risk to your organization. Subscribing to emerging threat notifications from Fortra ensures that you’re always on top of the threats that matter.
Title | CVE # | Published | Updated | Status |
---|---|---|---|---|
Commvault Remote Code Execution
|
CVE-2025-57788, CVE-2025-57789, CVE-2025-57790, CVE-2025-57791 | Active | ||
FortiSIEM Remote Unauthenticated Command Injection
|
CVE-2025-25256 | Active | ||
CrushFTP Zero-Day Exploited in the Wild
|
CVE-2025-54309 | Active | ||
Microsoft SharePoint Server Remote Code Execution Vulnerability
|
CVE-2025-53770 | Active | ||
FortiWeb Unauthenticated SQL Injection in GUI
|
CVE-2025-25257 | Active | ||
Multiple Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway
|
CVE-2025-5349, CVE-2025-5777, CVE-2025-6543 | Active | ||
Unauthenticated File Upload in SAP NetWeaver
|
CVE-2025-31324 | Active | ||
CrushFTP Authentication Bypass
|
CVE-2025-31161 | Active | ||
Multiple Vulnerabilities Impacting VMware ESXi, Workstation, and Fusion Updates
|
CVE-2025-22224, CVE-2025-22225, CVE-2025-22226 | Active | ||
Multiple Vulnerabilities Impacting rsync
|
CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747 | Active |