Výsledky hledání

výrobce: Fortinet× v celém archivu zrušit filtry

82 karet z 84 položek · strana 1 z 2 CZ · EN/orig

1

Multiples vulnérabilités dans les produits Fortinet (11 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.01 CVE-2026-22575 CVE-2026-26084 CVE-2026-84385 CVE-2026-84386 CVE-2026-84387 CVE-2026-84388 CVE-2026-84389 CVE-2026-84390 CVE-2026-84391 CVE-2026-84392 CVE-2026-84393 Fortinet FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans les produits Fortinet (11 septembre 2026)

1

NCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS

Fortinet heeft een kwetsbaarheid verholpen in FortiOS (Specifiek voor FortiSASE en FortiSwitchManager). De kwetsbaarheid bevindt zich in de cw_acd daemon in FortiOS en FortiSwitchManager. Deze daemon is kwetsbaar voor exploitatie door externe, niet-geauthenticeerde aanvallers. Door het verzenden van speciaal vervaardigde pakketten of verzoeken, kunnen aanvallers willekeurige code of commando's op de getroffen systemen uitvoeren. **UPDATE** Het Amerikaanse CISA heeft op 9 september de…

Fortinet NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS

10

Fortinet security advisory (AV26-023) - Update 1

Serial number: AV26-023Date: January 13, 2026Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to…

KEV ✓ EPSS 0.45 CVE-2025-25249 CVE-2025-47855 CVE-2025-64155 Fortinet CA

tg: zneužíváno tg: zranitelnost

· Cyber Centre Kanada · Fortinet security advisory (AV26-023) - Update 1

Fortinet security advisory (AV26-898)

Serial Number: AV26-898Date: September 9, 2026 As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products: FortiOS 7.6 Versions 7.6.1 to 7.6.6 FortiProxy 7.6 Versions 7.6.2 to 7.6.6 FortiPAM Chrome Extension 8.0 All versions FortiPAM Chrome Extension 7.4 All versions FortiSandbox 5.0 Versions 5.0.0 to 5.0.5 FortiSandbox 4.4 Versions 4.4.0 to 4.4.8 FortiSandbox Cloud 5.0 Versions 5.0.4 to 5.0.5 FortiSandbox PaaS 5.0 Versions 5.0.4 to 5.0.5 FortiMonitorOnSight 7.2…

Fortinet CA

tg: zranitelnost

· Cyber Centre Kanada · Fortinet security advisory (AV26-898)

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…

KEV ✓ EPSS 0.76 CVE-2025-25249 CVE-2026-19490 CVE-2026-20079 CVE-2026-87491 Fortinet Citrix Google Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE NCSC-2026-0355 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet Forti-producten

Fortinet heeft kwetsbaarheden verholpen in FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitorOnSight, FortiClient Windows, FortiSIEM en FortiSOAR. De kwetsbaarheden betreffen verschillende typen fouten in meerdere Fortinet-producten. De ernstigste kwetsbaarheid met kenmerk CVE-2026-26084 heeft een CVSS-score van 8,9. Het betreft een autorisatiekwetsbaarheid in Fortinet FortiSandbox waardoor een ongeauthenticeerde kwaadwillende via speciaal…

EPSS 0.00 CVSS 8.9 CVE-2026-26084 Fortinet NL FI

tg: zranitelnost

· NCSC-NL · NCSC-2026-0355 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet Forti-producten · NCSC-FI · FortiSandbox Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

SPOJENO PŘES CVE ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.

EPSS 0.01 CVSS 7.2 CVE-2026-84387 Fortinet US FI

tg: zranitelnost

· Zero Day Initiative · ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability · NCSC-FI · FortiSandbox Cron Job Injection in Remote Backup

FortiOS & FortiProxy ZTNA Portal Improper Certificate Validation

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.3, CVEs: CVE-2026-84393, Summary: An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website.

EPSS 0.00 CVSS 7.3 CVE-2026-84393 Fortinet FI

tg: zranitelnost

· NCSC-FI · FortiOS & FortiProxy ZTNA Portal Improper Certificate Validation

FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-84390, Summary: An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT

EPSS 0.01 CVSS 9.6 CVE-2026-84390 Fortinet FI

tg: zranitelnost tp: identita

· NCSC-FI · FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Improper Authentication of FortiPAM Server

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-84388, Summary: An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet…

CVSS 9.1 CVE-2026-84388 Fortinet FI

tg: zranitelnost

· NCSC-FI · Improper Authentication of FortiPAM Server

11

1

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a…

Fortinet Citrix Ivanti Palo Alto Networks US

tg: zneužíváno tg: rozbor tp: ransomware tp: špionáž

· Tenable Research · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

6

NCSC-2026-0300 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet FortiWeb

Fortinet heeft kwetsbaarheden verholpen in FortiWeb. De eerste kwetsbaarheid betreft een Improper Authentication in meerdere versies van FortiWeb, waardoor een externe, niet-geauthenticeerde aanvaller toegang kan krijgen tot de GUI- en CLI-interfaces door het indienen van willekeurige inloggegevens. Deze kwetsbaarheid treedt ook op bij FortiWeb-systemen die zijn geconfigureerd met Remote Radius Type Admin Authentication onder bepaalde niet-standaard instellingen. Hierdoor kan een aanvaller de…

Fortinet NL

· NCSC-NL · NCSC-2026-0300 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet FortiWeb

NCSC-2026-0299 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiManager

Fortinet heeft een kwetsbaarheid verholpen in FortiManager en FortiManager Cloud versies 7.2.5 tot en met 7.6.1. De kwetsbaarheid betreft een authenticatiebypass via een alternatieve route of kanaal. Een externe, niet-geauthenticeerde aanvaller die beschikt over een geldig certificaat kan zich voordoen als een FortiGate-apparaat dat wordt beheerd door FortiManager door speciaal opgemaakte FGFM-verzoeken te versturen. De oorzaak ligt in onjuiste toegangscontrolemechanismen binnen de getroffen…

Fortinet NL

· NCSC-NL · NCSC-2026-0299 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiManager

NCSC-2026-0296 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiClient

Fortinet heeft een kwetsbaarheid verholpen in FortiClient voor Windows. De kwetsbaarheid betreft een klassieke buffer overflow in de verwerking van DNS response packets. Deze ontstaat door een buffer copy operatie zonder controle op de grootte van de input. Hierdoor kan een niet-geauthenticeerde aanvaller kwaadaardige DNS responses opstellen en versturen. Bij succesvolle exploitatie kan de aanvaller willekeurige code uitvoeren binnen de context van de FortiClient applicatie.

Fortinet NL

· NCSC-NL · NCSC-2026-0296 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiClient

Multiples vulnérabilités dans les produits Fortinet (13 août 2026)

De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.34 CVE-2026-26035 CVE-2026-49975 CVE-2026-70465 CVE-2026-70466 CVE-2026-70467 CVE-2026-70468 CVE-2026-71407 CVE-2026-71408 Fortinet FR

· CERT-FR – avis · Multiples vulnérabilités dans les produits Fortinet (13 août 2026)

9

Fortinet security advisory (AV26-812)

Serial number: AV26-812Date: August 12, 2026 As of August 12, 2026, Fortinet is affected by a vulnerability in the following products: FortiClientWindows Prior to or equal to 7.2.11 Prior to or equal to 7.4.3 FortiManager Prior to or equal to 7.61 Prior to or equal to 7.4.5 Prior to or equal to 7.2.9 FortiManager Cloud Prior to or equal to 7.61 Prior to or equal to 7.4.5 Prior to or equal to 7.2.9 FortiWeb Prior to or equal to 8.0.2 Prior to or equal to 7.6.6 Prior to or equal to 7.4.11 Prior…

Fortinet CA

· Cyber Centre Kanada · Fortinet security advisory (AV26-812)

Siemens RUGGEDCOM APE1808

View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigation measures. The following versions of Siemens RUGGEDCOM APE1808 are affected: RUGGEDCOM APE1808 vers:all/* (CVE-2026-23573, CVE-2026-59839) CVSS Vendor Equipment Vulnerabilities v3 6.1 Siemens Siemens RUGGEDCOM APE1808…

EPSS 0.00 CVSS 6.1 CVE-2026-23573 CVE-2026-59839 Siemens Fortinet výroba a průmysl energetika doprava US

· CISA Advisories · Siemens RUGGEDCOM APE1808

UI DoS attack

CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

CVSS 5.0 Fortinet US

· Fortinet PSIRT · UI DoS attack

Stack buffer overflow in WAD

CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00

CVSS 5.1 Fortinet US

· Fortinet PSIRT · Stack buffer overflow in WAD

Server-Side Request Forgery (SSRF)

CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests Revised on 2026-08-12 00:00:00

CVSS 3.4 Fortinet US

· Fortinet PSIRT · Server-Side Request Forgery (SSRF)

FGFM Authentication Weakening via CLI Configuration

CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. Revised on 2026-08-12 00:00:00

CVSS 7.3 Fortinet US

· Fortinet PSIRT · FGFM Authentication Weakening via CLI Configuration

Content-Encoding WAF Evasion

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

CVSS 4.8 Fortinet US

· Fortinet PSIRT · Content-Encoding WAF Evasion

1

1

11

Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00

CVSS 6.9 Fortinet US

· Fortinet PSIRT · Supers override fails to properly override supervisor address

Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00

CVSS 5.9 Fortinet US

· Fortinet PSIRT · Stack Buffer Overflow in Log Report

SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00

CVSS 6.1 Fortinet US

· Fortinet PSIRT · SSL-VPN Reflected XSS

Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

CVSS 5.0 Fortinet US

· Fortinet PSIRT · Path traversal in CLI command allows deletion of root file system

Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00

CVSS 7.0 Fortinet US

· Fortinet PSIRT · Out of bounds read in GUI

Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00

CVSS 3.1 Fortinet US

· Fortinet PSIRT · Header injection in captive portal authentication form

Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00

CVSS 3.4 Fortinet US

· Fortinet PSIRT · Header injection in Web Filter warning page

2

Information och rekommendationer gällande säkerhet kring brandväggar

Brandväggar är en återkommande utmaning gällande angrepp från hotaktörer. Nu senast den uppmärksammade FortiBleed-läckan, där hotaktörer utnyttjar läckta inloggningsuppgifter i stor skala. [1] Med anledning av angrepp mot brandväggar publicerar CERT-SE information och rekommendationer till berörda organisationer i Sverige.

Fortinet SE

· CERT-SE · Information och rekommendationer gällande säkerhet kring brandväggar

Update #1: Angriffswelle gegen FortiGate Devices - "FortiBleed"

22. Juni 2026 Beschreibung Fortinet hat letzten Freitag, am 19.5.2026, nun auch ein offizielles Statement zu "FortiBleed" veröffentlicht. Wir hatten zuvor in einem Blog-Artikel unseren aktuellen Wissensstand beschrieben. Bei dieser Angriffswelle handelt es sich nicht um die Ausnutzung einer neuen Schwachstelle. Die Angreifer:innen verwenden stattdessen Zugangsdaten, die bei früheren Sicherheitsvorfällen (u. a. im Zusammenhang mit CVE-2025-59718, CVE-2025-59719 und CVE-2026-24858) erlangt wurden…

KEV ✓ EPSS 0.86 CVE-2025-59718 CVE-2025-59719 CVE-2026-24858 Fortinet telekomunikace AT

· CERT.at · Update #1: Angriffswelle gegen FortiGate Devices - "FortiBleed"

2

Útočníci získali přístup k desítkám tisíc firewallů Fortinet

Bezpečnostní výzkumníci upozornili na rozsáhlou kampaň zaměřenou na firewally a VPN brány Fortinet, při níž mělo být kompromitováno téměř 74 000 zařízení ve 194 zemích. Útočníci podle zveřejněných informací automatizovaně vyhledávali veřejně dostupná administrační rozhraní, získávali konfigurace zařízení a následně offline prolamovali přístupové údaje. Mezi údajně zasaženými organizacemi jsou nadnárodní společnosti, státní instituce i provozovatelé kritické infrastruktury. Případ zároveň…

Fortinet veřejná správa energetika vodárenství telekomunikace CZ

· CSIRT.CZ (CZ.NIC) · Útočníci získali přístup k desítkám tisíc firewallů Fortinet

1

1

2

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

CVSS 9.1 Fortinet US

· Fortinet PSIRT · Second-Order OS Command Injection via JSON Input on start vnc feature

Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

CVSS 6.0 Fortinet US

· Fortinet PSIRT · Restricted CLI escape using Lua