Versa Concerto is an orchestration and management platform for Versa Networks’ SD-WAN and SASE (Secure Access Service Edge) solutions. Widely deployed in enterprise and managed networking environments. CVE-2025-34025: Privilege escalation flaw enabling Docker container escape and host-level code execution. CVE-2025-34026: Traefik authentication bypass allowing unauthorized access to admin endpoints and internal Spring Boot Actuator data. CVE-2025-34026 was flagged for urgent attention and added to the CISA Known Exploited Vulnerabilities Catalog. CVE-2025-34027: Traefik authentication bypass leading to arbitrary file writes and full remote code execution via package upload endpoint.
Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.
Organizations are advised to apply vendor patches, restrict access to orchestration interfaces, and implement protective controls such as network segmentation and strict administrative access policies to limit exposure.
January 29, 2026: FortiGuard Labs released a Threat Signal.
January 22, 2026: CVE-2025-34026 was added to the CISA Known Exploited Vulnerabilities Catalog
Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.
Assisted Response Services
Attack Surface Hardening
Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.
Sources of information in support and relation to this Outbreak and vendor.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
