These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-84390 is a critical vulnerability in Fortinet FortiMonitorOnSight versions 7.2.0 through 7.2.2 and 7.2.4 through 7.2.7, allowing for improper access control due to the inclusion of sensitive information in source code. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Defenders should assess exposure and prioritize remediation efforts immediately. The vulnerability allows a [truncated]
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via network traffic. Organizations should review and apply patches or updates as necessary to prevent potential denial of service attacks. The CVE record was published on 2026-08-12T13:17:25.677Z and has not [truncated]
CVE-2026-70466 is an incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.5, 7.4, 7.2, and 7.0. This vulnerability may allow an attacker to bypass access control, potentially leading to improper access control. Organizations should review and update their systems to prevent potential exploitation. The CVE record was published on 2026-08-12 [truncated]
CVE-2026-59840 is a buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions. This vulnerability may allow an attacker to disclose information via an unspecified attack vector.
The CVE-2026-59839 vulnerability is a path traversal issue affecting various Fortinet products, including FortiOS, FortiPAM, and FortiProxy. This vulnerability may allow an attacker to execute unauthorized code or commands. Organizations should review their Fortinet product deployments, particularly those in versions listed as vulnerable, and take steps to mitigate this potential vulnerability. Affected p [truncated]
A stack-based buffer overflow vulnerability exists in various Fortinet products, including FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.0 through 1.8.2, and FortiProxy 7.4.0 through 7.4.13. This vulnerability may allow a privileged authenticated attacker to execute arbitrary code or commands via crafted HTTP requests. Organizations should review their Fortinet product deployments for [truncated]
CVE-2026-23573 is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability affecting Fortinet FortiOS, FortiPAM, and FortiProxy products. Authenticated remote users may execute code or commands via crafted requests. Security teams should review affected product deployments, assess operational impact, and prioritize patching or mitigation efforts.
CVE-2025-62826 is an Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability in Fortinet FortiOS and FortiProxy. The vulnerability, with a CVSS score of 3.1, may allow an attacker to inject arbitrary headers via crafted HTTP requests if they can intercept and modify a user's captive portal authentication request. This vulnerability affects Fortinet FortiOS 7.6.0 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T16:16:42.617Z and has not been modified since then. CVE-2025-62675 is an Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability affecting Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through [truncated]
A buffer over-read vulnerability exists in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, and FortiOS 6.4 all versions. This vulnerability may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. The vulnerability has a CVSS score of 4.3 and is [truncated]
CVE-2026-44279 is a MEDIUM-severity vulnerability affecting Fortinet FortiTokenAndroid versions 5.2, 6.1, and 6.2. An improper export of android application components vulnerability may allow attackers to disclose information via an exported Content Provider URI. The vulnerability was published on May 12, 2026, and modified on June 26, 2026. The CVSS score is 5.5. Fortinet has provided a vendor advisory f [truncated]
A critical improper access control vulnerability in Fortinet FortiAuthenticator allows unauthenticated remote attackers to execute unauthorized code or commands via crafted network requests. The vulnerability affects multiple versions across the 6.5, 6.6, and 8.0 release branches, with patches available in versions 6.5.7, 6.6.9, and 8.0.3 respectively. The CVSS 3.1 score of 9.8 reflects network attack vec [truncated]
A critical vulnerability, CVE-2026-26083, was found in Fortinet FortiSandbox products, including FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, and various FortiSandbox PaaS versions. This vulnerability allows an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. The CVSS score for this vulnerability is 9.8, ind [truncated]
Fortinet FortiDeceptor contains an argument injection vulnerability (CWE-88) in HTTP request handling for log file access. An authenticated attacker with read-only admin privileges can craft malicious HTTP requests to read arbitrary log files on affected systems. The vulnerability stems from improper neutralization of argument delimiters in command execution contexts. This is a medium-severity information [truncated]
Fortinet disclosed a SQL injection vulnerability (CWE-89) in its FortiNDR network detection and response platform on 12 May 2026, with subsequent modification on 18 May 2026. The flaw affects multiple FortiNDR release trains: versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.9, and all versions of 7.2, 7.1, and 7.0. An authenticated attacker can exploit this weakness via specially crafted HTTP requests to e [truncated]
A critical path traversal vulnerability, tracked as CVE-2026-39813, has been identified in Fortinet FortiSandbox versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. This vulnerability allows attackers to escalate privileges via specially crafted HTTP requests. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Organizations using affected versions of FortiSandbox should [truncated]
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS and on-premise versions may allow an attacker to gain information disclosure via an unspecified attack vector. The vulnerability affects Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 throug [truncated]
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attack [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-14T16:16:31.610Z and has not been modified since then. The SQL injection vulnerability in Fortinet FortiAnalyzer and FortiManager products allows a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API, affecting various versions including 7.6.0 through 7.6.4, 7 [truncated]
CVE-2026-21643 affects Fortinet FortiClient EMS and is publicly listed by CISA in the Known Exploited Vulnerabilities catalog, indicating observed exploitation and a need for prompt defensive action. The supplied corpus identifies the issue as an SQL injection vulnerability, but does not provide affected version ranges or deeper technical detail. Because it is on the KEV list, organizations should treat r [truncated]
CVE-2026-35616 affects Fortinet FortiClient EMS and is described as an improper access control vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-06, which means federal and enterprise defenders should treat it as actively exploited and prioritize remediation. The supplied corpus does not include vendor advisory details or a technical root-cause writeup, so defenders sh [truncated]
CVE-2026-24858 is a Fortinet authentication bypass vulnerability affecting multiple products and identified by CISA as known to be exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-27 with a remediation due date of 2026-01-30, making this a near-term priority for exposed Fortinet deployments. Fortinet and CISA advise organizations to assess exposure, apply vend [truncated]
CVE-2025-59718 is a Fortinet vulnerability in multiple products involving improper verification of a cryptographic signature. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-16 with a remediation due date of 2025-12-23, so defenders should treat it as an urgent remediation item. Because the available corpus is limited to the CVE title and KEV metadata, this debrief focuses on defen [truncated]
CVE-2025-58034 is a Fortinet FortiWeb OS command injection vulnerability that CISA lists in the Known Exploited Vulnerabilities (KEV) catalog. KEV inclusion means defenders should treat this as a high-priority issue, verify whether FortiWeb is deployed in their environment, and follow vendor and CISA guidance as soon as possible.
CVE-2025-64446 is a Fortinet FortiWeb path traversal vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2025-11-14. The official sources in this corpus identify the affected product family and the vulnerability class, but they do not include additional technical detail or a CVSS score. Because it is in KEV, defenders should treat it as an urgent remediation item and foll [truncated]
CVE-2025-25257 is a Fortinet FortiWeb SQL injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-07-18. That KEV status means defenders should treat it as a high-priority issue even though the supplied corpus does not include CVSS data or affected-version details.
CVE-2019-6693 is a Fortinet FortiOS vulnerability involving hard-coded credentials. CISA lists it in the Known Exploited Vulnerabilities catalog and marks it as associated with known ransomware campaign use, so exposed FortiOS systems should be treated as urgent remediation targets. Follow Fortinet's vendor guidance and CISA's required-action guidance immediately; if mitigations are unavailable, CISA advi [truncated]
CVE-2025-32756 is a Fortinet multiple-products stack-based buffer overflow vulnerability that CISA listed in the Known Exploited Vulnerabilities catalog on 2025-05-14. The public record confirms the issue name and the fact that it is known to be exploited, but the supplied sources do not provide affected product versions, exploit details, or vendor remediation specifics. Treat this as a high-priority expo [truncated]
CVE-2025-59719 is a critical, network-exploitable authentication-bypass issue described as improper verification of a cryptographic signature in a SAML response. The supplied CVE text says an unauthenticated attacker could bypass FortiCloud SSO login authentication by sending a crafted SAML response message. Because the supplied source corpus is internally inconsistent about the affected product, this ite [truncated]
CVE-2025-58413 is described in the supplied advisory corpus as a high-severity stack-based buffer overflow associated with Siemens RUGGEDCOM APE1808. The source metadata says the flaw can allow unauthorized code or commands via specially crafted packets, and the advisory was first published on 2025-05-13 with later republication updates through 2026-02-12. The corpus also contains an internal mismatch: th [truncated]