Improper access control on API endpoints
CVSSv3 Score: 9.1
An Improper Access Control vulnerability in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or...
Command injection in CLI
CVSSv3 Score: 6.1
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability in FortiAP,...
Out-of-bounds access in CAPWAP daemon
CVSSv3 Score: 8.3
An Out-Of-Bounds Write vulnerability in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender...
DoS due to unsafe function in signal handler
CVSSv3 Score: 5.2
A use of potentially Dangerous Function vulnerability in FortiAnalyzer and FortiManager API may allow an authenticated attacker...
OTP Disclosure via Exported TokenContentProvider
CVSSv3 Score: 5.0
An improper export of Android application components in FortiTokenAndroid may allow other applications on the device to...
User controlled SQL commands
CVSSv3 Score: 5.1
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in FortiNDR may...
OS command injection in CLI
CVSSv3 Score: 6.5
An OS command injection vulnerabtility in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute...
SQL command injection in administrative portal
CVSSv3 Score: 6.3
An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in FortiMail may...
Cushman & Wakefield – 310,431 breached accounts
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters...




