Fortinet reported two vulnerabilities affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy related to FortiCloud SSO authentication. The first vulnerability, an Authentication Bypass (CWE-288), allows…
On March 10, 2026, Fortinet released a security advisory addressing eleven vulnerabilities in its core products, including a high-severity stack-based buffer overflow in FortiManager (CVE-2025-54820) that allows remote…
Fortinet's Single Sign-On (SSO) vulnerabilities, CVE-2025-59718 and CVE-2025-59719, are being actively exploited by attackers to gain unauthorized administrative access to FortiGate firewalls. These flaws allow…
The Canadian Centre for Cyber Security has issued an alert regarding critical vulnerabilities affecting Fortinet products, specifically related to FortiCloud SSO Login Authentication Bypass. These vulnerabilities may…
Fortinet has patched critical vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. These security defects, which allow for authentication bypass and could lead to configuration leaks and code…
Ivanti has issued security updates for a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) product. This flaw could allow remote, unauthenticated attackers to execute arbitrary JavaScript code,…
Fortinet has released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. The vulnerabilities,…
Fortinet has confirmed that attackers are actively exploiting a vulnerability in FortiCloud's single sign-on (SSO) authentication, affecting even fully patched devices. The exploitation allows unauthorized access, with…
Recent advisories detail multiple vulnerabilities affecting various software products. CVE-2026-21509, published on January 26, 2026, is under active exploitation and could allow unauthenticated remote code execution.…
More than 25,000 Fortinet devices with FortiCloud SSO enabled are exposed to remote attacks due to a critical authentication bypass vulnerability tracked as CVE-2025-59718. The U.S. has the highest number of affected…