CVE-2025-6737: Securden Unified Pam

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.

Affected products

  • Securden Unified Pam: from 9.0, before 11.3.1 (fixed in 11.3.1)

Published 2025-08-25. Last modified 2026-06-17.