詳細検索

[February 2026 Edition] Summary of Vulnerabilities to Address Now|FortiSIEM, Cisco, Apple

Avatar
by 似里
4 min read

[February 2026 Edition] Summary of Vulnerabilities to Address Now|FortiSIEM, Cisco, Apple
Translated from 日本語 • View original
似里
似里

Hello! I'm a Colorkrew infrastructure and security engineer. I set a New Year's goal to "run every day to tone my body", but I'm a little worried about how long it will last. . .

So, we have summarized the vulnerabilities that need to be addressed as we continued last month.
For those involved in SOC/security operations, we will identify the most recent vulnerabilities to watchCybersecurity
and the Known
Exploited Vulnerbilities Catalog published by the Infrastructure Security Agency (CISA) and the Common Vulnerabilities and Exposures (CVEs) published by The MITRE Corporation Based on Records, we have written explanations + how to deal with it. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.

What is Known Exploited Vulnerabilities Catalog?

The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.

What is Common Vulnerabilities and Exposures?

Common Vulnerabilities and Exposures (CVEs) are identifiers assigned to vulnerabilities in individual products published by The MITRE Corporation. An organization of security professionals, such as security vendors, product development vendors, and researchers, evaluates reported vulnerabilities and assigns identifiers.

Overview of each vulnerability and how to address it

CVE-2025-64155

Product/Scope of Influence

  • FortiSIEM 7.4: 7.4.0
  • FortiSIEM 7.3: 7.3.0 ~ 7.3.4
  • FortiSIEM 7.2: 7.2.0 ~ 7.2.6
  • FortiSIEM 7.1: 7.1.0 ~ 7.1.8
  • FortiSIEM 7.0: 7.0.0 ~ 7.0.4
  • FortiSIEM 6.7: 6.7.0 ~ 6.7.10

CVSS Score 9.8

Overview/Key Takeaways FortiSIEM is a Security Information and Event Management (SIEM) product provided by Fortinet. This vulnerability allows an unauthenticated attacker to send a crafted TCP request due to improper handling of special characters used in OS commands (CWE-78. The vulnerability does not affect Collector nodes, only Super and Worker nodes.

Points to Deal with

A temporary workaround is to close the port (7900) for phMonitor. However, permanently, upgrade each product.

  • FortiSIEM 7.4: 7.4.1 ~
  • FortiSIEM 7.3: 7.3.5 ~
  • FortiSIEM 7.2: 7.2.7 ~
  • FortiSIEM 7.1: 7.1.9 ~
  • FortiSIEM 7.0: Migrating to the latest product version
  • FortiSIEM 6.7: Migrating to the latest product version

References


CVE-2025-20393

Product/Scope of Influence

  • Cisco Secure Email
    • 14.0.0-698
    • 13.5.1-277
    • 13.0.0-392
    • 14.2.0-620
    • 13.0.5-007
    • 13.5.4-038
    • 14.2.1-020
    • 14.3.0-032
    • 15.0.0-104
    • 15.0.1-030
    • 15.5.0-048
    • 15.5.1-055
    • 15.5.2-018
    • 16.0.0-050
    • 15.0.3-002
    • 16.0.0-054
    • 15.5.3-022
    • 16.0.1-017
  • Cisco Secure Email and Web Manager
    • 13.6.2-023
    • 13.6.2-078
    • 13.0.0-249
    • 13.0.0-277
    • 13.8.1-052
    • 13.8.1-068
    • 13.8.1-074
    • 14.0.0-404
    • 12.8.1-002
    • 14.1.0-227
    • 13.6.1-201
    • 14.2.0-203
    • 14.2.0-212
    • 12.8.1-021
    • 13.8.1-108
    • 14.2.0-224
    • 14.3.0-120
    • 15.0.0-334
    • 15.5.1-024
    • 15.5.1-029
    • 15.5.2-005
    • 16.0.0-195
    • 15.5.3-017
    • 16.0.1-010
    • 15.0.1-035
    • 16.0.2-088

CVSS Score 10.0

Overview/Key Points

Cisco Secure Email is Cisco's suite of email security products designed to protect corporate email communications. Its main purpose is to detect and block spam, phishing, and malware-containing emails, and is placed at the front of the email infrastructure in many companies. The vulnerability exploited this time allows an attacker to execute arbitrary commands with root privileges. (CWE-20)

Points to Deal with

Security patches have already been distributed, so update to the latest version. It has been released as updating by following the steps below. Please refer to the official documentation for details.

  1. Select System Administration > System Upgrade.
  2. Click Upgrade Options.
  3. Click Download and Install.
  4. Select the release you want to upgrade to.
  5. In the Upgrade Preparation section, select the appropriate option as needed.
  6. Click Proceed to start the upgrade. The progress is displayed in the progress bar.

References


CVE-2025-31201

Product/Scope of Influence

  • visionOS: ~2.4
  • iOS/iPadOS: ~18.4
  • tvOS: ~18.4
  • macOS: ~15.4

CVSS Score 9.8

Overview/Key Points

A vulnerability has been reported in the operating system of all Apple products that could bypass the processing of pointer authentication codes (PACs). Pointer authentication codes (PACs) are used to prevent memory destruction. The system software and built-in apps use PACs to prevent tampering with function pointers and return addresses (code pointers). (Pointer Authentication Code - Apple Platform Security)

Points to Deal with

Security patches have already been distributed by Apple. Update each product to the latest version.

  • visionOS: 2.4.1
  • iOS/iPadOS: 18.4.1
  • tvOS: 18.4.1
  • macOS: 15.4.1

References

What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.

If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.

Related Articles