logo

Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution

ID: b8689d55-ebfd-5f43-86b7-1f24e2235009

STIX ID: report--b8689d55-ebfd-5f43-86b7-1f24e2235009

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-05-12

...
...

Multiple vulnerabilities affecting a range of Fortinet products (FortiAnalyzer, FortiSandbox, FortiClientEMS, FortiDDoS-F, FortiSOAR, FortiWeb, FortiOS, FortiManager, FortiNDR, FortiVoice, and others) have been disclosed, including several high-severity issues — notably unauthenticated heap-based buffer overflow and OS command injection leading to potential arbitrary code execution — alongside numerous lower-severity flaws (SQL injection, path traversal, XSS, insecure credential/storage issues). Successful exploitation of the most severe vulnerabilities could allow attackers to run code as service accounts, potentially leading to program installation, data access/modification, or account creation depending on privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.