Home/News

Security & Lifecycle News

Aggregated from vendor advisories, security research, and industry publications.

FortiGuard PSIRT Advisories

SQL command injection in administrative portal

CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privi…

FortiGuard PSIRT Advisories

User controlled SQL commands

CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attack…

FortiGuard PSIRT Advisories

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authentica…

FortiGuard PSIRT Advisories

OS command injection in CLI

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands v…

FortiGuard PSIRT Advisories

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system…

FortiGuard PSIRT Advisories

OTP Disclosure via Exported TokenContentProvider

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an e…

FortiGuard PSIRT Advisories

Out-of-bounds access in CAPWAP daemon

CVSSv3 Score: 8.3 An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwi…

Cisco Security Advisories

Cisco IoT Field Network Director Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute c…

Cisco CVE-2026-20167 CVE-2026-20168 CVE-2026-20169
↑ Top