A vulnerability marked as critical has been reported in Milestone Systems XProtect VMS. This impacts an unknown function of the component MIP Webhooks API. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2025-0836. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure.
Cybersecurity company Arctic Wolf said it observed active intrusions involving malicious single sign-on (SSO) logins on FortiGate appliances on December 12, 2025. The attacks exploit two critical authentication bypasses (CVE-2025-59718 and CVE-2025-59719