logo

FortiOS and FortiSwitchManager Vulnerability Let Remote Attackers Execute Arbitrary Code

ID: 6ba1b4d0-f056-5b7f-a303-034dd928bbff

STIX ID: report--6ba1b4d0-f056-5b7f-a303-034dd928bbff

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive summary:** Fortinet disclosed a critical heap-based buffer overflow in the cw_acd daemon affecting multiple FortiOS branches, FortiSASE releases, and FortiSwitchManager versions that can allow unauthenticated remote code execution; administrators are urged to apply vendor patches (listed upgrade paths) immediately or implement mitigations such as disabling fabric access on interfaces and blocking CAPWAP control UDP ports (5246–5249).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.