Home Blog Page 159

Reflected XSS in HA cluster

CVSSv3 Score: 5.3 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox may allow an attacker to perform an XSS attack via crafted HTTP requests. Revised on 2025-12-09 00:00:00 - Read more

Read-only admin could obtain admin configuration secrets

CVSSv3 Score: 2.6 An improper access control vulnerability in FortiAuthenticator Web UI may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests. Revised on 2025-12-09 00:00:00 - Read more

Path traversal vulnerability in administrative interface

CVSSv3 Score: 7.7 Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities in FortiVoice may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands. Revised on 2025-12-09 00:00:00 - Read more

OS command injection in multiple endpoints

CVSSv3 Score: 7.0 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in FortiSandbox may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests. Revised on 2025-12-09 00:00:00 - Read more

OS command injection in GUI backup options

CVSSv3 Score: 6.9 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in FortiSandbox GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests. Revised on 2025-12-09 00:00:00 - Read more

Multiple authenticated SQL injection via extraParam

CVSSv3 Score: 6.8 An improper neutralization of special elements used in an SQL command ('SQL injection') in FortiVoice may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests. Revised on 2025-12-09 00:00:00 - Read more

Multiple authenticated OS Command Injections via API

CVSSv3 Score: 6.7 An OS command injection vulnerabtility in FortiExtender API may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request. Revised on 2025-12-09 00:00:00 - Read more

Multiple Fortinet Products’ FortiCloud SSO Login Authentication Bypass

CVSSv3 Score: 9.1 An Improper Verification of Cryptographic Signature vulnerability in FortiOS, FortiWeb, FortiProxy and FortiSwitchManager mayallow an unauthenticated attacker to bypass the FortiCloud SSO loginauthentication via a crafted SAML message, if that feature is enabled on the device.Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an...

Missing authorization on log access

CVSSv3 Score: 2.6 A Direct Request ('Forced Browsing') vulnerability in FortiAuthenticator logs may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints. Revised on 2025-12-09 00:00:00 - Read more

Insufficient Session Expiration in SSLVPN

CVSSv3 Score: 5.3 An Insufficient Session Expiration vulnerability in FortiOS SSLVPN may allow an attacker to maintain access to network resources via an active session not terminated after a user's password change under particular conditions outside of the attacker's control Revised on 2025-12-09 00:00:00 - Read more

Latest article

GreatXML zero-day BitLocker bypass doesn’t seem to work, yet

A disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit...

New Windows Zero-Day Claims BitLocker Bypass Amid Microsoft Disclosure Fight

A new Windows zero-day reportedly bypasses BitLocker, adding pressure on Microsoft as researchers debate the exploit’s real-world impact. The post New Windows Zero-Day Claims BitLocker...

Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks

One of the most persistent hacking groups in the world has found a new way to stay hidden. The threat actor known as...

Ransomware Payment Crypto Laundering Platform Taken Out by FBI and Europol

Domain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and others - Read...