Safeguard
Tag

fortinet

Safeguard articles tagged "fortinet" — guides, analysis, and best practices for software supply chain and application security.

43 articles

Vulnerability Analysis

CVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerability

CVE-2026-35616 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-06.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability

CVE-2026-21643 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-13.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability

CVE-2026-39808 affects Fortinet FortiSandbox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-16.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability

CVE-2026-25089 affects Fortinet FortiSandbox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-16.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CVE-2025-68686 affects Fortinet FortiOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-27.

Sep 17, 20264 min read
Vulnerability Analysis

CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVE-2025-25249 affects Fortinet Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-09.

Sep 17, 20263 min read
Vulnerability Analysis

FortiClient EMS and FortiWeb Add Five More Confirmed-Exploited CVEs to Fortinet's Year

A SQL injection and an access-control bug in FortiClient EMS, a path traversal and command injection pair in FortiWeb — Fortinet's endpoint management and WAF products join the list.

Sep 16, 20264 min read
Vulnerability Analysis

Two FortiOS CVEs Span Six Release Lines Going Back Years

A heap-based buffer overflow and an information-exposure bug in FortiOS, both confirmed exploited in 2026, span version ranges reaching back through years of release history.

Sep 16, 20264 min read
Vulnerability Analysis

FortiSandbox Had Two Command Injection CVEs on the Same Day — the Irony Is the Point

Fortinet FortiSandbox, built to detonate suspicious files safely, had two command injection vulnerabilities confirmed exploited on the same day in July 2026.

Sep 16, 20264 min read
Vulnerability Analysis

CVE-2025-59718 in FortiOS: FortiCloud SSO SAML Bypass

An unauthenticated SAML message manipulation lets attackers log in as admin on FortiGate, FortiWeb, and FortiProxy. We unpack the bug and the IR steps.

Aug 2, 20266 min read
Vulnerability Response

CVE-2025-64446 in Fortinet FortiWeb: Patch Posture & SBOM Response

FortiWeb path traversal + RCE scored CVSS 9.1 and entered CISA KEV after months of targeted exploitation. Defender playbook for the WAF emergency.

Jul 20, 20267 min read
Vulnerability Analysis

FortiOS CVE-2024-21762 Explained: The SSL VPN Out-of-Bounds Write RCE

CVE-2024-21762 is a pre-authentication out-of-bounds write in the FortiOS SSL VPN daemon that allows remote code execution. Here is the timeline, root cause, detection, and the full list of fixed versions.

Jul 4, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.