PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23573 Fortinet CVE debrief

CVE-2026-23573 is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability affecting Fortinet FortiOS, FortiPAM, and FortiProxy products. Authenticated remote users may execute code or commands via crafted requests. Security teams should review affected product deployments, assess operational impact, and prioritize patching or mitigation efforts.

Vendor
Fortinet
Product
FortiOS
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-08-11
Advisory published
2026-07-14
Advisory updated
2026-08-11

Who should care

Security teams, administrators, and operators responsible for Fortinet FortiOS, FortiPAM, and FortiProxy products should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing affected product deployments, assessing operational impact, and prioritizing patching or mitigation efforts. Vulnerability management and security teams should monitor for suspicious activity and exception tracking, and restrict access to sensitive areas of the affected systems.

Technical summary

The vulnerability, CVE-2026-23573, affects Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.0.0 through 1.8.0, and FortiProxy 7.2.0 through 7.2.9, 7.4.0 through 7.4.3. An authenticated remote user may execute code or commands via crafted requests due to improper neutralization of input during web page generation. Security teams should focus on patching affected products and implementing compensating controls.

Defensive priority

Authenticated remote users may execute code or commands via crafted requests in Fortinet FortiOS, FortiPAM, and FortiProxy products.

Recommended defensive actions

  • Inventory and verify affected Fortinet products and versions.
  • Apply vendor patches or updates for affected products.
  • Implement compensating controls, such as web application firewalls.
  • Monitor for suspicious activity and exception tracking.
  • Restrict access to sensitive areas of the affected systems.

Evidence notes

The CVE-2026-23573 record indicates an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in various Fortinet products. Authenticated remote users may execute code or commands via crafted requests. Affected products include Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.0.0 through 1.8.0, and FortiProxy 7.2.0 through 7.2.9, 7.4.0 through 7.4.3.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T16:16:51.823Z and has not been modified since then.