FORTINET: 📅 Published on March 11, 2025 (Revised May 25, 2026)
FORTINET Security Advisory Published Date: March 11, 2025 (Revised May 25, 2026) CVE: CVE-2025-26466 Advisory Summary ❗️ Security Alert: Pre-authentication Denial of Service Vulnerability in OpenSSH (CVE-2025-26466) Fortinet has identified a significant pre-authentication Denial of Service (DoS) vulnerability in the OpenSSH package, tracked as CVE-2025-26466, with a CVSSv3 severity score of 5.9. The flaw involves […]
FORTINET: 📅 Published on November 18, 2025 (Revised May 27, 2026)
FORTINET Security Advisory Published Date: November 18, 2025 (Revised May 27, 2026) Advisory Summary ⚠️ Improper Privilege Management Vulnerability in Fortinet Infrastructure ⚠️ Fortinet has identified a low-severity security vulnerability (CVSSv3 score: 1.8) affecting FortiOS, FortiProxy, and FortiPAM products. This Improper Privilege Management issue (CWE-269) enables an authenticated administrator to circumvent the trusted host policy […]
FORTINET: FortiOS Logging Sensitive 2FA Data
FORTINET Security Advisory Published Date: October 14, 2025 | Revised June 8, 2026 Advisory Summary A newly identified vulnerability in FortiOS, rated with a CVSSv3 score of 2.6, involves the insertion of sensitive two-factor authentication (2FA) information into log files and the output of diagnostic commands. This CWE-532 weakness could potentially expose sensitive 2FA details […]
FORTINET: ▶️ Critical Second-Order OS Command Injection in FortiSandbox Web UI
FORTINET Security Advisory Published Date: June 9, 2026 Advisory Summary Fortinet has disclosed a severe security vulnerability (CVSSv3 score 9.1) affecting FortiSandbox, including FortiSandbox Cloud and PaaS Web UI versions. This flaw stems from improper neutralization of OS command elements (CWE-78), leading to a second-order OS command injection risk. Exploitation can allow unauthenticated attackers to […]
FORTINET: 🛑 Restricted CLI Escape Using Lua in FortiOS and FortiProxy
FORTINET Security Advisory Published Date: June 9, 2026 Advisory Summary A significant security concern has been identified in Fortinet’s FortiOS and FortiProxy platforms involving an Internal Asset exposed to an Unsafe Debug Access Level or State (CWE-1244). This vulnerability permits an authenticated administrator to execute Lua scripts through specifically crafted CLI commands, potentially leading to […]
FORTINET: 📅 Published on June 9, 2026
FORTINET Security Advisory Published Date: June 9, 2026 Advisory Summary 🔔 Security Alert: Improper Access Control in FortiPortal API Endpoints Fortinet has disclosed a vulnerability rated with a CVSSv3 score of 6.2 affecting FortiPortal API endpoints. The issue arises from improper access control (CWE-284), which could enable a remote attacker, possessing an organization user role, […]
CISCO: ➤ Cisco Catalyst SD-WAN Privilege Escalation Risk
CISCO Security Advisory Published Date: June 9, 2026 CVE: CVE-2026-20182 Advisory Summary A critical security flaw has been identified in the CLI interfaces of Cisco Catalyst SD-WAN Controller (formerly vSmart), Catalyst SD-WAN Manager (formerly vManage), and Catalyst SD-WAN Validator (formerly vBond). Authenticated local attackers with netadmin privileges can exploit insufficient input validation by uploading specially […]
CISCO: High-Risk Cisco Catalyst SD-WAN Manager Privilege Escalation
CISCO Security Advisory Published Date: Not specified CVE: CVE-2026-20245 Advisory Summary 📅 Published Date: June 8, 2026 A critical vulnerability (CVE-2026-20245) has been identified in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw enables an authenticated local attacker with netadmin privileges to execute arbitrary commands as the root user by uploading […]
CISCO: – Customers must urgently upgrade to the fixed software releases detailed in Cisco’s Catalyst SD-WAN Security Advisory (issued May 14, 2026).
CISCO Security Advisory Published Date: Not specified CVE: CVE-2026-20245 Advisory Summary 📅 June 5, 2026 ➤➤ SECURITY ALERT: High-Risk Privilege Escalation Vulnerability in Cisco Catalyst SD-WAN Manager A critical vulnerability (CVE-2026-20245) has been identified in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw allows a local attacker with netadmin privileges to […]
CISCO: – Upgrade to the fixed software as soon as it becomes available, in line with Cisco’s Catalyst SD-WAN Security Advisory from May 14, 2026.
CISCO Security Advisory Published Date: June 5, 2026 CVE: CVE-2026-20245 Advisory Summary ⬢ Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability – Critical Alert ⬢ A high-severity vulnerability (CVE-2026-20245) has been identified in the CLI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). This flaw allows an authenticated local attacker with netadmin privileges to execute arbitrary […]