CVE-2025-60425: Nagios Fusion

High severity, CVSS 8.6. EPSS: 1% chance of exploitation in the next 30 days.

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

Affected products

  • Nagios Fusion: version 2024 only

Published 2025-10-27. Last modified 2026-06-17.