Authentication rate-limit bypass permits to brute force admin logins

CVSSv3 Score: 7.3 An Improper Control of Interaction Frequency vulnerability in FortiWeb may allow a remote unauthenticated attacker to bypass...

Protected hostname bypass

CVSSv3 Score: 5.0 An authentication bypass by spoofing vulnerability in FortiWeb protected hostname feature may allow a remote unauthenticated attacker...

Authentication Lockout Bypass via Race Condition

CVSSv3 Score: 3.4 An improper restriction of excessive authentication attempts vulnerability in FortiManager and FortiAnalyzer may allow an attacker to...

OS Command injection in FortiWeb API

CVSSv3 Score: 6.7 An OS Command Injection vulnerability in FortiWeb API may allow an authenticated attacked to execute arbitrary commands...

Null Pointer Dereference in Anti-Defacement feature

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability in FortiWeb may allow an authenticated attacker to crash the HTTP daemon...

Format string vulnerability in fazsvcd

CVSSv3 Score: 6.5 A use of externally-controlled format string vulnerability in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon...

Local privilege escalation via improper symlink following

CVSSv3 Score: 7.4 A UNIX symbolic link (Symlink) Following vulnerability in FortiClientLinux may allow a local and unprivileged user to...

Buffer overflow via fgtupdates service

CVSSv3 Score: 7.0 A Stack-based Buffer Overflow vulnerability in FortiManager fgtupdates service may allow a remote unauthenticated attacker to execute...

Lack of TLS Certificate Validation during initial SSO Authentication

CVSSv3 Score: 6.3 An improper certificate validation vulnerability in the FortiManager GUI may allow a remote unauthenticated attacker to view...

Latest article

Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface...

Torrance, United States / California, June 11th, 2026, CyberNewswire Criminal IP by AI SPERA, a cyber threat intelligence platform delivering decision-ready intelligence and attack...

Readers reply: Experts say we should use passkeys, but can a smartphone pin really...

The long-running series in which readers answer other readers’ questions on subjects ranging from trivial flights of fancy to profound scientific and philosophical conceptsThis...

Weekly Metasploit Update: New Kerberos/Certificate tracing options, and multiple new modules

New Tracing OptionsAs hard as we try to ensure that Metasploit is bug free, issues inevitably come up. Whether you’re running a module on...