LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
vulnerabilitycritical

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.

zeroday.news ·

Photo: Jug81 (CC BY-SA 4.0) via Wikimedia Commons

Fortinet has released patches addressing critical vulnerabilities found in its FortiMonitorOnSight product and a related Chrome extension. The reported flaws are described as critical and unauthenticated, enabling attackers to bypass authentication mechanisms and potentially proxy a user's browser traffic.

The primary mechanism of these vulnerabilities involves an unauthenticated bypass of security controls. This type of flaw typically allows an attacker to gain unauthorized access to a system or service without needing valid credentials. In the context of FortiMonitorOnSight, this could mean an attacker could interact with the monitoring system or its associated components as if they were an authenticated user.

The ability to proxy a user's browser traffic is a significant concern. This implies that an attacker could potentially intercept, view, or even manipulate web traffic flowing through the compromised system or extension. Such a capability could lead to various malicious activities, including session hijacking, credential theft, or the injection of malicious content into legitimate web pages.

FortiMonitorOnSight is a solution designed for monitoring IT infrastructure, providing visibility into network performance, application health, and system status. Products in this category often handle sensitive operational data and are integrated deeply within an organization's network, making vulnerabilities particularly impactful. The associated Chrome extension likely facilitates interaction with the FortiMonitorOnSight platform directly from the browser, extending its functionality to end-users.

The scope of impact for such vulnerabilities can vary. For the FortiMonitorOnSight product itself, organizations utilizing the vulnerable versions would be at risk. For the Chrome extension, individual users who have installed the extension would be exposed. Given the critical nature and unauthenticated access, the potential for widespread exploitation before patches are applied is a significant concern.

Mitigation for this class of vulnerability invariably involves applying the vendor-supplied patches as soon as possible. Organizations are typically advised to identify all instances of the affected product and extension within their environment and follow Fortinet's patching instructions diligently. Additionally, reviewing access logs for any signs of unusual activity prior to patching is a recommended security practice.

This incident underscores the ongoing challenge of securing complex IT environments, particularly those involving both on-premise solutions and browser-based components. Critical vulnerabilities that allow unauthenticated access and traffic manipulation remain a top concern for cybersecurity professionals, highlighting the importance of continuous security auditing and prompt patch management across all layers of an organization's infrastructure.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.