CVE-2025-6737: Securden Unified Pam
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions.
Affected products
- Securden Unified Pam: from 9.0, before 11.3.1 (fixed in 11.3.1)
Published 2025-08-25. Last modified 2026-06-17.