See how fortinet compares to other vendors in security performance
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Fortinet has disclosed CVE-2026-59835, an unauthenticated VNC exposure affecting FortiSandbox 5.0.0 - 5.0.2 and 4.4.3 - 4.4.8. The flaw can allow remote attackers to access the VNC server of virtual machines performing malware analysis via network requests, potentially exposing live sandbox sessions. Patches have been released by Fortinet on 14 July, and organizations using affected versions should update as soon as possible
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
CISA dropped an alert on June 18 telling everyone with internet-facing FortiGate firewalls and SSL VPN gateways to lock things down. The campaign is being called FortiBleed.
The important part: this is NOT a new zero-day. CISA and Fortinet both say it comes from reused and un-rotated credentials from earlier infostealer leaks, combined with brute-force activity. Fortinet says no new vulnerability exists in their products.
CISA says the activity "involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices." SOCRadar says it is worse, citing "over 86,644 confirmed working credentials across 194 countries."
Researcher Bob Diachenko found an exposed server with valid VPN creds, usernames, emails, and plaintext passwords, attributed to a Russian-speaking cybercrime group.
Kevin Beaumont, working with Hudson Rock, verified the data is real: "I have worked with several orgs listed, and can confirm the logins and passwords are real. Many of the devices sampled are on fairly recent patches."
Even 25+ character passwords showed up in plaintext, so these were pulled from harvested infostealer logs, not cracked.
Huntress identified 845 impacted partner orgs. TechCrunch named alleged victims including Accenture, Comcast, Foxconn, Lenovo, Oracle, Samsung, Siemens, and PwC. Bitsight confirmed active exploitation with tunneling tools Chisel and Neo-reGeorg.
NCSC, Canada's Cyber Centre (AL26-014), the FBI, and HKCERT all put out warnings too.
What CISA wants you to do now: kill all SSL VPN and admin sessions, reset every VPN and admin password, turn on phishing-resistant MFA, and dig through logs for unauthorized access or lateral movement. Canada also says audit for rogue accounts like forticloud-sync and forticloud-tech, and verify patches for CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719.
So basically, if you run Fortinet edge gear, today is a password rotation day whether you planned one or not.
https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
Hello all! With the crazy explosion of vulnerabilities being disclosed lately, I thought it might be helpful to have a weekly post about the top CVE's from the week before. Mods, let me know if this breaks any rules or if it should be posted differently. My intention is just community building and trying to help others out that are in the same situation as our team.
Four vulns stood out to me from the past week. All of them are on CISA's KEV list, which means there is evidence of active exploitation. The two internet-facing ones should be prioritized first is applicable.
1. CVE-2026-0257, Palo Alto PAN-OS GlobalProtect auth bypass
If you have GlobalProtect exposed, this is not one to let sit too long. Attackers are able to forge GlobalProtect session cookies and connect to the VPN without valid credentials.
Affected: PAN-OS firewalls with the GlobalProtect portal or gateway enabled.
Why it matters: The CVSS score is only 4.0, which looks “medium” on paper, but that score feels misleading here. It is KEV-listed, exploited in the wild, unauthenticated, and sitting on an internet-facing VPN service.
Action: upgrade to a fixed PAN-OS release now, or disable the auth-override feature as an interim step. Also review GlobalProtect logs for sessions you cannot account for.
2. CVE-2026-35616: Fortinet FortiClient EMS pre-auth API bypass
This one is nasty because of what EMS manages.
It is a pre-auth bypass that can let an attacker push scripts to managed endpoints. Arctic Wolf reported exploitation in May, including EKZ infostealer activity disguised as a Fortinet update.
Affected: FortiClient EMS 7.4.5 through 7.4.6.
Why it matters: EMS has a bunch of downstream control. If someone can abuse it, the impact can quickly move from just “one exposed management service” to “many managed endpoints.”
Action: Confirm your EMS version and apply the hotfix. I’d also review managed-endpoint policies and Remote Access Profiles for anything you did not create recently.
3. CVE-2026-48172: LiteSpeed cPanel plugin privilege escalation to root
This one mainly matters for web hosts, MSPs, and anyone running cPanel with LiteSpeed.
Any authenticated cPanel user can run scripts as root through the plugin’s Redis JSON API. It was reportedly exploited as a zero-day before the fix shipped.
Affected: LiteSpeed user-end cPanel plugin versions 2.3 through 2.4.4.
Why it matters: CVSS 9.8. Added to KEV on May 26, with the federal remediation deadline already passed on May 29.
Action: Update the plugin to 2.4.5 or later. IOC to check in the cPanel logs:
cpaneljsonapifunc=redisAble
4. CVE-2026-34926: Trend Micro Apex One on-prem directory traversal
This is not really a front-door bug, but it is still worth attention because of the blast radius.
An attacker with admin access to the Apex One server can inject code into the agent update channel and push it to managed endpoints.
Affected: On-premise Trend Micro Apex One. The SaaS version is not impacted.
Why it matters: KEV-listed and exploited in the wild. Federal deadline is June 4. The caveat is that it obviously already requires prior admin access to the server, so treat it as an escalation/lateral-movement risk.
Action: Apply Trend Micro’s fix. If you cannot patch immediately, restrict who and what can reach the Apex One management server.
Not every KEV entry deserves a full on fire drill, but the Palo Alto and Fortinet items seem like the ones I would want handled first if they were in my environment.
Let me know if this format is helpful at all and I'll do another one next week if it's worthwhile to the community!
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>