Patch these first
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-25089exploited | 9.8 | critical | fortisandbox | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort | 88d ago |
9 CVEs published in the last four months and 7 stories. Exploited flaws first.
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-25089exploited | 9.8 | critical | fortisandbox | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort | 88d ago |

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities affecting Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog. The flaws include OS command injection in FortiSandbox and a deserialization vulnerability in SharePoint that allows for remote code execution without authentication. Microsoft has confirmed active exploitation of the SharePoint flaw.

A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.