PatchSiren cyber security CVE debrief
CVE-2026-23573 Fortinet CVE debrief
CVE-2026-23573 is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability affecting Fortinet FortiOS, FortiPAM, and FortiProxy products. Authenticated remote users may execute code or commands via crafted requests. Security teams should review affected product deployments, assess operational impact, and prioritize patching or mitigation efforts.
- Vendor
- Fortinet
- Product
- FortiOS
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-08-11
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-08-11
Who should care
Security teams, administrators, and operators responsible for Fortinet FortiOS, FortiPAM, and FortiProxy products should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing affected product deployments, assessing operational impact, and prioritizing patching or mitigation efforts. Vulnerability management and security teams should monitor for suspicious activity and exception tracking, and restrict access to sensitive areas of the affected systems.
Technical summary
The vulnerability, CVE-2026-23573, affects Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.0.0 through 1.8.0, and FortiProxy 7.2.0 through 7.2.9, 7.4.0 through 7.4.3. An authenticated remote user may execute code or commands via crafted requests due to improper neutralization of input during web page generation. Security teams should focus on patching affected products and implementing compensating controls.
Defensive priority
Authenticated remote users may execute code or commands via crafted requests in Fortinet FortiOS, FortiPAM, and FortiProxy products.
Recommended defensive actions
- Inventory and verify affected Fortinet products and versions.
- Apply vendor patches or updates for affected products.
- Implement compensating controls, such as web application firewalls.
- Monitor for suspicious activity and exception tracking.
- Restrict access to sensitive areas of the affected systems.
Evidence notes
The CVE-2026-23573 record indicates an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in various Fortinet products. Authenticated remote users may execute code or commands via crafted requests. Affected products include Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.0.0 through 1.8.0, and FortiProxy 7.2.0 through 7.2.9, 7.4.0 through 7.4.3.
Official resources
-
CVE-2026-23573 CVE record
CVE.org
-
CVE-2026-23573 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Source reference
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T16:16:51.823Z and has not been modified since then.