home.social

#fortisandbox — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fortisandbox, aggregated by home.social.

fetched live
  1. CISA Warns of Active Exploits Targeting FortiSandbox Flaws

    Critical FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, are under active attack by hackers, allowing them to execute malicious commands without needing login credentials. These severe vulnerabilities, scoring 9.1, require immediate attention to prevent devastating remote code execution attacks.

    osintsights.com/cisa-warns-of-

    #Fortisandbox #Cve202639808 #Cve202625089 #OsCommandInjection #Cisa

  2. 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking.  The post 3 Recently Patc...

    #Vulnerabilities #exploited #FortiBleed #Fortinet #FortiSandbox #vulnerability

    Origin | Interest | Match
  3. Fortinet Sandbox Flaws Under Active Exploitation

    Critical Fortinet Sandbox vulnerabilities are under active attack, with hackers exploiting flaws like CVE-2026-39813, a severe path traversal bug that allows authentication bypass. Fortinet patched these bugs in April, but users must upgrade ASAP to avoid being compromised.

    osintsights.com/fortinet-sandb

    #Fortinet #Fortisandbox #Cve202639813 #PathTraversal #AuthenticationBypass

  4. Fortinet Flaws Exposed to Active Exploitation

    Critical vulnerabilities in Fortinet's FortiSandbox platform are under active attack, with multiple flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, being exploited by hackers just 24 hours after security updates were issued.

    osintsights.com/fortinet-flaws

    #Fortinet #Fortisandbox #Cve202639813 #Cve202639808 #Cve202625089

  5. #BSI WID-SEC-2025-0347: [NEU] [mittel] #Fortinet #FortiSandbox: Schwachstelle ermöglicht Cross-Site Scripting

    Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortinet FortiSandbox ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.

    wid.cert-bund.de/portal/wid/se

  6. Happy Patch Tuesday from your friends at Fortinet. 13 security advisories, 15 vulnerabilities. No mention of exploitation in the wild:

    • FG-IR-23-087 CVE-2023-45590 (9.6 critical) [FortiClient Linux] Remote Code Execution due to dangerous nodejs configuration
    • FG-IR-23-345 CVE-2023-45588 and CVE-2024-31492 (8.2 high) FortiClientMac - Lack of configuration file validation
    • FG-IR-23-419 CVE-2023-47542 (6.7 medium) FortiManager - Code Injection via Jinja Template
    • FG-IR-23-288 CVE-2023-48785 (4.8 medium) FortiNAC-F - Lack of certificate validation
    • FG-IR-23-413 CVE-2023-48784 (6.7 medium) FortiOS - Format String in CLI command
    • FG-IR-23-224 CVE-2024-23662 (5.3 medium ) FortiOS - Web server ETag exposure
    • FG-IR-23-493 CVE-2023-41677 (7.5 high) FortiOS & FortiProxy - administrator cookie leakage
    • FG-IR-23-454 CVE-2024-23671 (8.1 high) FortiSandbox - Arbitrary file delete on endpoint
    • FG-IR-24-060 CVE-2024-31487 (5.9 medium) FortiSandbox - Arbitrary file read on endpoint
    • FG-IR-23-416 CVE-2023-47541 (6.7 medium) FortiSandbox - Arbitrary file write on CLI leading to arbitrary code execution
    • FG-IR-23-411 CVE-2023-47540 (6.7 medium) FortiSandbox - Command injection impacting CLI command
    • FG-IR-23-489 CVE-2024-21755 and CVE-2024-21756 (8.8 high) FortiSandbox - OS command injection on endpoint
    • FG-IR-24-009 CVE-2024-26014 (5.3 medium) SMTP Smuggling (analyst note: third party vulnerability)

    #PatchTuesday #Fortinet #FortiManager #vulnerability #FortiSandbox #FortiOS #FortiProxy

Share on Mastodon

Enter the server where you have an account.