logo

Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

ID: 48a838af-970e-5d80-ab1e-6b098d771687

STIX ID: report--48a838af-970e-5d80-ab1e-6b098d771687

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet published advisories on April 14, 2026, for 11 vulnerabilities across FortiSandbox, FortiAnalyzer, FortiManager, FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager. The batch includes two Critical unauthenticated flaws — an OS command injection (CVE-2026-39808) and a JRPC API path traversal enabling authentication bypass (CVE-2026-39813) — a High-rated unauthenticated heap overflow in oftpd (CVE-2026-22828), plus multiple Medium/Low path traversal, XSS, and SQL injection issues; administrators are urged to apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.