XSS via back button

CVSSv3 Score: 7.9 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox may allow an...

Firewall policy bypass in FSSO Terminal Services Agent

CVSSv3 Score: 3.8 An Improper Verification of Source of a Communication Channel vulnerability in FortiOS FSSO Terminal Services Agent may...

CVE-2026-21519 Desktop Window Manager Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. - Read more

Arbitrary XML file write in FCConfig

CVSSv3 Score: 6.4 An Improper Link Resolution Before File Access vulnerability in FortiClient Windows may allow a local low-privilege attacker...

SSL-VPN Symlink Persistence Patch Bypass

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in FortiOS SSL-VPN may allow a remote...

Request smuggling attack in FortiOS GUI

CVSSv3 Score: 5.2 An HTTP request smuggling vulnerability in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http...

Missing authorization on CSV user import

CVSSv3 Score: 6.8 A missing authorization vulnerability in FortiAuthenticator may allow a read-only admin to make modification to local users...

LDAP authentication bypass in Agentless VPN and FSSO

CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability in FortiOS fnbamd may allow an unauthenticated attacker to bypass...

Format String Vulnerability in CAPWAP fast-failover mode

CVSSv3 Score: 6.7 A Use of Externally-Controlled Format String vulnerability in FortiGate may allow an authenticated admin to execute unauthorized...

Latest article

CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT

A new open-source cybersecurity platform called CyberSentinel AI v3.0 has emerged as a significant development in autonomous security tooling, combining 33 real-world penetration testing...

JCPenney – 368,418 breached accounts

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through...

Threat actor adds advanced ‘EDR killer’ tools to ransomware-as-a-service platform

One of the world’s top ransomware groups has given its criminal affiliates access to advanced tools capable of successfully disabling...