For those involved in SOC/security operations, we will identify the most recent vulnerabilities to watchCybersecurity
and the Known Exploited Vulnerbilities Catalog published by the Infrastructure Security Agency (CISA) and the Common Vulnerabilities and Exposures (CVEs) published by The MITRE Corporation Based on Records, we have written explanations + how to deal with it. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.
What is Known Exploited Vulnerabilities Catalog?
The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.
What is Common Vulnerabilities and Exposures?
Common Vulnerabilities and Exposures (CVEs) are identifiers assigned to vulnerabilities in individual products published by The MITRE Corporation. An organization of security professionals, such as security vendors, product development vendors, and researchers, evaluates reported vulnerabilities and assigns identifiers.
Overview of each vulnerability and how to address it
CVE-2025-11001
Product/Area of Influence 7-Zip (Older Versions with Ver. 24.09)
CVSS Score
7.0
Overview/Key Points
A remote code execution vulnerability has been identified due to 7-Zip directory traversal. This allows a remote attacker to execute arbitrary code on an environment with a target version of 7-Zip installed. This vulnerability is linked to a . This is caused by improper handling of symbolic links in zip files.
Points to Deal with
Promptly update to the latest version published on August 3, 2025. Check out the official update information here.
CVE-2025-13016
Product/Scope of Influence
- Firefox (older versions including ver.144.0.2)
- Firefox ESR (older version including ver.140.4)
- Thunderbird (~ver. 144.01 and older versions)
CVSS Score
7.5
Overview/Key Points
It is believed to be a vulnerability in a WebAssembly component written in JavaScript.
Points to Deal with
Use the official release notes below to update to the latest version.
CVE-2025-49752
Product/Scope of Influence Azure Bastion
CVSS Score
10.0
Overview/Key Takeaways An Azure Bastion Elevation of Privilege Vulnerability has been identified as a vulnerability equivalent to CWE-294: Authentication Bypass by Capture-replay. A vulnerability that allows a malicious user to bypass authentication on the network by stealing an authentication token once it has been issued.
Points of Action Based on official information from Microsoft, it is said that there is nothing that can be done on the user's side, but there have been no confirmed cases where this vulnerability has been exploited, and the risk of exploitation is considered low.
CVE-2025-58034
Product/Scope of Influence
- FortiWeb(ver8.0.0~8.0.1)
- FortiWeb(ver7.6.0~7.6.5)
- FortiWeb(ver7.4.0~7.4.10)
- FortiWeb(ver7.2.0~7.2.11)
- FortiWeb(ver7.0.2~7.0.11)
CVSS Score
6.7
Overview/Key Points A vulnerability equivalent to CWE-78 has been identified as a vulnerability that poses a risk of OS command injection. An authenticated attacker could execute malformed HTTP requests or CLI commands against a target version of the product.
Takeaways According to Fortinet's announcement, it is recommended to update each major version. For each major version, update to the latest version below.
- For FortiWeb (ver8.0.0~8.0.1) **, ver.8.0.2 or the latest version
- For FortiWeb (ver7.6.0~7.6.5) **, ver.7.6.6 or the latest version
- For FortiWeb (ver7.4.0~7.4.10) **, ver.7.4.11 or the latest version
- For FortiWeb (ver7.2.0~7.2.11) **, ver.7.2.12 or the latest version
- For FortiWeb (ver7.0.2~7.0.11) **, ver.7.0.12 or the latest version
What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.
If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.