CISCO: đź“… August 12, 2026
CISCO Security Advisory Published Date: Not specified Advisory Summary ⬛ 🛡️ Title: Cisco PSIRT “Advance Notification” for Aug 19, 2026 Security Advisories đź’ˇ Information (What’s happening) Cisco PSIRT has issued an advance notice that it will publish new security advisories on August 19, 2026, including fixed software releases for multiple product lines. BroadWorks Industrial Ethernet […]
FORTINET: 🗓️ Calendar • August 12, 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary 🏷️ ⬛ UI DoS attack — FortiOS slow HTTP DoS (unauthenticated) 🔎 What happened / why it matters FortiOS contains an “Allocation of Resources Without Limits or Throttling” weakness (CWE-770, CVSSv3 5.0) that could let an unauthenticated attacker trigger a slow HTTP Denial of Service against […]
FORTINET: 🗓️ Calendar • 12 Aug 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary đź”” â–˛ Security Alert: Stack Buffer Overflow in FortiOS WAD (Explicit Proxy) đź§© What’s happeningA stack-based buffer overflow (CWE-121) has been reported in FortiOS explicit proxy, affecting the WAD daemon. Under specific conditions, an attacker may be able to achieve remote code/command execution in the context […]
FORTINET: đź“… Aug 12, 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary 🔎 đź§© SSRF in FortiSIEM GUI (CWE-918) — Risk to internal reachabilityFortiSIEM GUI contains a Server-Side Request Forgery (SSRF) vulnerability (CVSSv3 3.4) that may allow an authenticated attacker to trigger the FortiSIEM server to make HTTP requests using specially crafted requests. Internal pivoting potential: SSRF can […]
FORTINET: 🗓️ Calendar: August 12, 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary ⬛ Title: â—† Heap overflow (kernel driver) — missing size validation 🔎 Summary (for market professionals): FortiClient for Windows contains a buffer copy flaw where input size is not properly validated (CWE-120). The issue can enable an unauthenticated attacker to craft or alter DNS responses toward […]
FORTINET: đź“… Published: August 12, 2026
FORTINET Security Advisory Published Date: Not specified CVE: CVE-2026-49975 Advisory Summary 🏷️ 〖 HTTP/2 Bomb — CVE-2026-49975 〗 Fortinet PSIRT highlights CVE-2026-49975 (CVSS v3 5.8) — a memory allocation with excessive size flaw in Apache HTTP Server’s mod_http, enabling Denial of Service (DoS) through crafted HTTP requests (often described in “HTTP/2 bomb” terms). Service degradation […]
FORTINET: 🗓️ 📅 Aug 12, 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary ## 🛡️🔔 FortiManager/Cloud FGFM Authentication Weakening (CWE-288) â—† Overview (What happened?) FortiManager and FortiManager Cloud contain an authentication bypass issue (CWE-288) that could allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager. The attack relies on a specific CLI option set through […]
FORTINET: 🗓️ Calendar 12 August 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary 🔎 ⚙️ Content-Encoding WAF Evasion — FortiWeb (PSIRT FG-IR-26-157) FortiWeb WAF has a vulnerability where an incomplete set of disallowed inputs (CWE-184) may let an unauthenticated attacker bypass existing WAF policies. The issue is tied to content encoding behaviors, meaning carefully crafted requests may evade enforcement. […]
FORTINET: đź“… Aug 12, 2026
FORTINET Security Advisory Published Date: Not specified Advisory Summary ⬛ Title: ➤ Broken access control in the RADIUS type admin group (FortiWeb) ⚠️ What’s new / impact (CWE-287, Improper Authentication | CVSS 8.8) FortiWeb’s Remote Radius Type Admin Authentication—when configured with specific, non-default settings—can expose an authentication weakness where a remote, unauthenticated attacker may be […]
HPE: 🗓️ Calendar • Aug 11, 2026
HPE Security Advisory Published Date: Not specified Advisory Summary 🏷️ Advisory Snapshot (HPESBHF05092 rev.1) 🔎 HPE has published HPESBHF05092 rev.1 addressing a Local Disclosure of Information vulnerability affecting HPE StoreEasy servers that use certain Intel processors and include/enable the Intel Trust Domain Extensions (Intel TDX) module. The bulletin ties to Intel-SA-01419 and references the 2026.2 […]