logo

Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution

ID: a66c8ece-6656-5a1b-b391-c9b493ac7efe

STIX ID: report--a66c8ece-6656-5a1b-b391-c9b493ac7efe

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2025-11-18

Date Updated: 2026-04-27

...
...

**Executive summary:** Multiple critical and moderate vulnerabilities were disclosed in Fortinet products (FortiADC, FortiOS, FortiWeb, FortiClient, FortiExtender, FortiSandbox, FortiVoice, FortiMail, FortiPAM, FortiProxy, FortiSwitchManager, FortiADC logs, etc.), including remote code execution, stack/heap buffer overflows, command and SQL injection, and privilege/credential issues. At least one vulnerability (CVE-2025-58034 in FortiWeb) is reported as observed in the wild; organizations using affected Fortinet devices or services should prioritize patching and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.