CVEs Targeting Remote Access Technologies in 2025
The exploitation of vulnerabilities targeting remote access technologies to gain initial access is continuing relentlessly also during 2025, with initial access brokers, and in general opportunistic and targeted threat actors, quite active in leveraging software flaws to break into organizations.
- Post author:Paolo Passeri
- Post published:October 7, 2025
- Post category:Cyber Attacks Timelines / Security
- Post comments:0 Comments
- Reading time:1 min read
Views: 28,719
Last modified: October 7, 2025
[View Paolo Passeri's LinkedIn profile]
[View Paolo Passeri's Mastdon profile]
The exploitation of vulnerabilities targeting remote access technologies to gain initial access is continuing relentlessly also during 2025, with initial access brokers, and in general opportunistic and targeted threat actors, quite active in leveraging software flaws to break into organizations.
Similarly to what i did in 2024, I am collecting the list of vulnerabilities targeting security technologies defending the perimeter, which have been exploited so far. As you will notice in the list, a good portion of them are 0-days discovered during 2025, but there are also some vulnerabilities that were disclosed (and patched) a few years ago, but are still exploited by threat actors, since they were left unpatched, an aspect that reinforces the importance of strong security procedures throughout the organization.
Distribution of Vulnerabilities by Vendor **
No Data Found
Below the links to the vendors’ bulletins for the exploited vulnerabilities (whenever they were available)
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
https://blog.lumen.com/the-j-magic-show-magic-packets-and-where-to-find-them/
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003
https://security.paloaltonetworks.com/CVE-2025-0108
https://support.checkpoint.com/results/sk/sk182336
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022
**https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018**
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0011
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788
**https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018
https://psirt.global.sonicwall.com/vuln-detail/snwlid-2025-0011**
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424
**https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW**
| ID | Date Reported | Date Occurred | Date Discovered | Author | Target | Vulnerability | Attack | Target Class | Attack Class | Country | Link | Vendor Bulletin | Vendor |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | 08/01/2025 | - | - | Unknown Threat Actors | Unknown Organization(s) | Ivanti warns that threat actors exploited a Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 in zero-day attacks to install malware on appliances. | Malware | Unknown | Unknown | Unknown | Ivanti | ||
| 2 | 10/01/2025 | Since at least early December2024 | Early December2024 | ? | Multiple Organizations | Researchers at Arctic Wolf observe a recent campaign affecting Fortinet FortiGate firewall devices with management interfaces exposed on the public internet, exploiting CVE-2024-55591. Few days later the security product maker confirms that the critical vulnerability is “being exploited in the wild.” | Unknown | Multiple Industries | Unknown | Unknown | Fortinet | ||
| 3 | 23/01/2025 | - | - | Unknown Threat Actors | Unknown Organization(s) | SonicWall alerts customers of CVE-2025-23006, a critical security flaw impacting its Secure Mobile Access (SMA) 1000 Series appliances that it said has been likely exploited in the wild as a zero-day. | Unknown | Unknown | Unknown | Unknown | Sonicwall |
[...]