A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
Fortinet reported two vulnerabilities affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy related to FortiCloud SSO authentication. The first vulnerability, an Authentication Bypass (CWE-288), allows…
Fortinet has released security updates to address critical vulnerabilities (CVE-2025-59718 and CVE-2025-59719) affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager products. Users and administrators are…
A critical path-traversal vulnerability (CVE-2025-64446) in Fortinet's FortiWeb web application firewall has been exploited by threat actors since early October 2025. This flaw allows unauthenticated attackers to create…
Fortinet has patched critical vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. These security defects, which allow for authentication bypass and could lead to configuration leaks and code…
Ivanti has issued security updates for a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) product. This flaw could allow remote, unauthenticated attackers to execute arbitrary JavaScript code,…
Fortinet has released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. The vulnerabilities,…
Fortinet has confirmed that attackers are actively exploiting a vulnerability in FortiCloud's single sign-on (SSO) authentication, affecting even fully patched devices. The exploitation allows unauthorized access, with…
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
More than 25,000 Fortinet devices with FortiCloud SSO enabled are exposed to remote attacks due to a critical authentication bypass vulnerability tracked as CVE-2025-59718. The U.S. has the highest number of affected…