FORTINET Security Advisory

Published Date: July 14, 2026

Advisory Summary

A vulnerability rated with a CVSSv3 score of 6.9 has been identified in the FortiSIEM Windows Agent related to the ‘Supers Override’ feature. The flaw stems from an Improper Restriction of Communication Channel to Intended Endpoints (CWE-923), which could allow an attacker on the same local network to spoof the supervisor’s hostname. This spoofing can lead to arbitrary code execution, potentially compromising the Windows device.

This security risk is particularly alarming because it leverages network-level spoofing, a technique that, if exploited, bypasses intended communication restrictions. Organizations utilizing the ‘Supers Override’ functionality in FortiSIEM should prioritize patching and verifying network environments to prevent unauthorized code execution.

Maintaining vigilance around communication channel restrictions is essential, especially as attackers increasingly exploit network proximity and device configurations.

-923

Reference: Vendor Advisory