logo

Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution

ID: 3f32d6ce-21e9-51a0-8d57-be09dafcbe04

STIX ID: report--3f32d6ce-21e9-51a0-8d57-be09dafcbe04

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities were disclosed in Fortinet products, including unauthenticated SQL injection and RCE vectors in FortiClientEMS and FortiSandbox, an LDAP authentication bypass in FortiOS fnbamd, and several lower-severity issues across FortiClient, FortiGate, FortiAuthenticator, and FortiOS (each with CVE identifiers). Successful exploitation of the most severe flaws could allow arbitrary code execution in the context of service accounts, potentially enabling installation of programs, data theft or modification, and creation of privileged accounts depending on service privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.