LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Fortinet

9 CVEs published in the last four months and 7 stories. Exploited flaws first.

Critical3
High6
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-25089exploited9.8criticalfortisandboxA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort88d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-260839.8criticalfortisandboxA missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4116d ago
CVE-2026-442779.8criticalfortiauthenticatorA improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthe116d ago
CVE-2026-25089exploited9.8criticalfortisandboxA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fort88d ago
CVE-2025-538448.8highfortiosA out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 116d ago
CVE-2026-598358.6highfortisandboxA exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.53d ago
CVE-2026-598417.5highfortisiemA improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAg53d ago
CVE-2025-533797.5highfortiauthenticatorA out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all 53d ago
CVE-2026-598367.5highforticlientemsA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.453d ago
CVE-2025-536817.2highfortimailAn improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vu116d ago

Filter the full tracker by Fortinet

Our coverage of Fortinet

vulnerability

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.

ransomwarecritical

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

ransomwarecritical

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.

CVE-2026-25089critical

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added critical vulnerabilities affecting Fortinet FortiSandbox and Microsoft SharePoint to its Known Exploited Vulnerabilities catalog. The flaws include OS command injection in FortiSandbox and a deserialization vulnerability in SharePoint that allows for remote code execution without authentication. Microsoft has confirmed active exploitation of the SharePoint flaw.

CVE-2026-24858high

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

fortinetcritical

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

fortinethigh

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

The UK's National Cyber Security Centre has released guidance for organizations utilizing Fortinet products. This advisory comes in response to a widespread campaign that has been observed targeting Fortinet firewalls and VPN gateways.