ZZOps Center
LIVE DATA REFRESH OVER 01:00
Lettertype
LettergrootteWordt op dit apparaat bewaard

SECURITY & SERVICE HEALTH

Operationeel overzicht

FortiGate kwetsbaarheden en de actuele beschikbaarheid van kritieke cloud- en telecomdiensten.

LAATSTE CONTROLE19 aug 2026, 00:56Automatisch iedere minuut
FORTIGATE ADVISORIES15in actuele PSIRT-feed
3 hoge prioriteit
ENREACH NLOperationeel5 dienstgroepen
Geen verstoring
MICROSOFT 365Availablepublieke globale status
Geen globale storing
DIENSTEN MET IMPACT0van 2 externe platforms
Alles stabiel

FORTINET PSIRT

FortiGate security advisories

FortiGuard openen ↗
15 advisories zichtbaarCVSS 3.x
7.3Hoog
FG-IR-26-160

FGFM Authentication Weakening via CLI Configuration

An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate.

5.1Middel
FG-IR-26-161

Stack buffer overflow in WAD

A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.

5.0Middel
FG-IR-26-162

UI DoS attack

An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests.

4.1Middel
FG-IR-26-154

Buffer overread in authd and wad daemon

A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

3.4Laag
FG-IR-26-152

Header injection in Web Filter warning page

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.

3.1Laag
FG-IR-26-153

Header injection in captive portal authentication form

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.

5.0Middel
FG-IR-26-151

Path traversal in CLI command allows deletion of root file system

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands.

6.1Middel
FG-IR-26-150

SSL-VPN Reflected XSS

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests.

5.9Middel
FG-IR-26-148

Stack Buffer Overflow in Log Report

A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.

7.5Hoog
FG-IR-25-1052

LDAP authentication bypass in Agentless VPN and FSSO

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration.

3.9Laag
FG-IR-24-257

Information Disclosure on SSLVPN endpoint

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL.

6.0Middel
FG-IR-26-143

Restricted CLI escape using Lua

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands.

2.6Laag
FG-IR-24-452

Insertion of Sensitive 2FA Information in logs and debug command

An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command.

1.8Laag
FG-IR-25-545

Trusted hosts bypass via SSH

An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.

8.3Hoog
FG-IR-26-123

Out-of-bounds access in CAPWAP daemon

An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device