fortinet
Safeguard articles tagged "fortinet" — guides, analysis, and best practices for software supply chain and application security.
43 articles
CVE-2026-35616: Fortinet FortiClient EMS Improper Access Control Vulnerability
CVE-2026-35616 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-06.
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection Vulnerability
CVE-2026-21643 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-13.
CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808 affects Fortinet FortiSandbox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-16.
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-25089 affects Fortinet FortiSandbox and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-16.
CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2025-68686 affects Fortinet FortiOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-27.
CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVE-2025-25249 affects Fortinet Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-09.
FortiClient EMS and FortiWeb Add Five More Confirmed-Exploited CVEs to Fortinet's Year
A SQL injection and an access-control bug in FortiClient EMS, a path traversal and command injection pair in FortiWeb — Fortinet's endpoint management and WAF products join the list.
Two FortiOS CVEs Span Six Release Lines Going Back Years
A heap-based buffer overflow and an information-exposure bug in FortiOS, both confirmed exploited in 2026, span version ranges reaching back through years of release history.
FortiSandbox Had Two Command Injection CVEs on the Same Day — the Irony Is the Point
Fortinet FortiSandbox, built to detonate suspicious files safely, had two command injection vulnerabilities confirmed exploited on the same day in July 2026.
CVE-2025-59718 in FortiOS: FortiCloud SSO SAML Bypass
An unauthenticated SAML message manipulation lets attackers log in as admin on FortiGate, FortiWeb, and FortiProxy. We unpack the bug and the IR steps.
CVE-2025-64446 in Fortinet FortiWeb: Patch Posture & SBOM Response
FortiWeb path traversal + RCE scored CVSS 9.1 and entered CISA KEV after months of targeted exploitation. Defender playbook for the WAF emergency.
FortiOS CVE-2024-21762 Explained: The SSL VPN Out-of-Bounds Write RCE
CVE-2024-21762 is a pre-authentication out-of-bounds write in the FortiOS SSL VPN daemon that allows remote code execution. Here is the timeline, root cause, detection, and the full list of fixed versions.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.