Výsledky hledání

výrobce: Fortinet× typ: zranitelnost× v celém archivu zrušit filtry

16 karet z 16 položek CZ · EN/orig

5

FortiSandbox Cron Job Injection in Remote Backup

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 6.7, CVEs: CVE-2026-84387, Summary: An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS 6.7 CVE-2026-84387 Fortinet FI

tg: zranitelnost

NCSC-FI ·

FortiOS & FortiProxy ZTNA Portal Improper Certificate Validation

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.3, CVEs: CVE-2026-84393, Summary: An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website.

CVSS 7.3 CVE-2026-84393 Fortinet FI

tg: zranitelnost

NCSC-FI ·

FortiSandbox Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.9, CVEs: CVE-2026-26084, Summary: An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests.

CVSS 8.9 CVE-2026-26084 Fortinet FI

tg: zranitelnost

NCSC-FI ·

FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-84390, Summary: An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT

CVSS 9.6 CVE-2026-84390 Fortinet FI

tg: zranitelnost tp: identita

NCSC-FI ·

Improper Authentication of FortiPAM Server

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-84388, Summary: An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet…

CVSS 9.1 CVE-2026-84388 Fortinet FI

tg: zranitelnost

NCSC-FI ·

11

ZTNA Portal Improper Certificate Validation

CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00

CVSS 7.3 Fortinet US

tg: zranitelnost

Fortinet PSIRT ·

Open Redirect on FortiSIEM

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

CVSS 2.8 Fortinet US

tg: zranitelnost

Fortinet PSIRT ·

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

CVSS 9.1 Fortinet US

tg: zranitelnost

Fortinet PSIRT ·

Cron Job Injection in Remote Backup

CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00

CVSS 6.7 Fortinet US

tg: zranitelnost

Fortinet PSIRT ·

Broken Access control on Websocket streams

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00

CVSS 4.9 Fortinet US

tg: zranitelnost

Fortinet PSIRT ·