An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests.
Virtual Patch named "FG-VD-10009598.0day." is available in FMWP db update 26.071.
2026-08-12: Initial publication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
