<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Fortinet</title><description>Actively exploited vulnerabilities affecting Fortinet products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/fortinet.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-68686</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-68686</guid><description>This vulnerability in Fortinet FortiOS allows a remote, unauthenticated attacker to bypass a previously issued patch that addressed a symbolic link persistence mechanism — a technique attackers use to maintain access after an initial compromise. Critically, exploitation requires the attacker to have already gained filesystem-level access through a separate vulnerability. The danger is that defenders who believed the earlier patch fully closed the persistence gap may still have compromised systems that remain accessible to attackers.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiOS</category></item><item><title>CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-25089</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-25089</guid><description>This vulnerability allows an unauthenticated attacker — meaning no login credentials are required — to inject and execute arbitrary operating system commands on affected Fortinet FortiSandbox systems simply by sending crafted HTTP requests. FortiSandbox is a security product used to analyze suspicious files and network traffic, so a compromise of it could undermine an organization&apos;s entire threat detection capability and provide attackers a foothold in a sensitive part of the network.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category></item><item><title>CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-39808</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-39808</guid><description>This vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker — meaning no login credentials are required — to inject and execute operating system commands by sending specially crafted HTTP requests. Because FortiSandbox is a security analysis platform often positioned at critical network chokepoints, a successful exploit could give attackers a foothold with significant privileges inside the environment, potentially undermining the very infrastructure meant to detect threats.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category></item><item><title>CVE-2026-21643 — Fortinet FortiClient EMS SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-21643</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-21643</guid><description>This SQL injection flaw in Fortinet FortiClient EMS allows an unauthenticated attacker to send crafted HTTP requests and execute arbitrary code or commands on the system — no credentials required. FortiClient EMS is widely used to manage endpoint security policies, so a compromise could give attackers control over endpoint configurations across an entire organization, potentially serving as a launchpad for broader network intrusion.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category></item><item><title>CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-35616</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-35616</guid><description>FortiClient EMS, Fortinet&apos;s endpoint management server, contains an improper access control flaw that lets unauthenticated attackers execute arbitrary code or commands by sending crafted requests. Because no credentials are required to exploit this, the attack surface is broad — any network-reachable EMS instance could be compromised. Successful exploitation gives an attacker control over the management plane, potentially affecting all endpoints managed by that EMS server.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category></item><item><title>CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-24858</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-24858</guid><description>This vulnerability affects Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy when FortiCloud SSO authentication is enabled. An attacker who has a legitimate FortiCloud account and at least one registered device could exploit an authentication bypass flaw to log into devices registered under entirely different customer accounts. This cross-account access risk means a malicious or compromised FortiCloud user could gain unauthorized control over other organizations&apos; Fortinet devices without needing their credentials.</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>Multiple Products</category></item><item><title>CVE-2025-59718 — Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-59718</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-59718</guid><description>This vulnerability allows an unauthenticated attacker to bypass FortiCloud SSO login by crafting a malicious SAML message — essentially forging proof of identity without valid credentials. Because SAML is used for single sign-on, a successful exploit could grant full access to Fortinet management interfaces across FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb without knowing any password. The breadth of affected products makes this a high-priority issue for any organization using Fortinet infrastructure with FortiCloud SSO enabled.</description><pubDate>Tue, 16 Dec 2025 00:00:00 GMT</pubDate><category>Fortinet</category><category>Multiple Products</category></item><item><title>CVE-2025-58034 — Fortinet FortiWeb OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-58034</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-58034</guid><description>This vulnerability in Fortinet&apos;s FortiWeb web application firewall allows an authenticated attacker to inject OS-level commands through crafted HTTP requests or CLI commands, resulting in unauthorized code execution on the underlying system. Because FortiWeb sits at the network perimeter protecting web applications, a compromised instance could give attackers deep footholds into infrastructure, potentially exposing backend systems and sensitive traffic to full attacker control.</description><pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiWeb</category></item><item><title>CVE-2025-64446 — Fortinet FortiWeb Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-64446</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-64446</guid><description>This vulnerability in Fortinet FortiWeb allows an unauthenticated attacker — meaning no credentials are required — to traverse file paths and execute administrative commands by sending specially crafted HTTP or HTTPS requests. Because it requires no authentication, the attack surface is broad: any FortiWeb instance reachable over the network could be targeted. Successful exploitation gives an attacker administrative control over the appliance, potentially exposing protected web applications and internal infrastructure behind it.</description><pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiWeb</category></item><item><title>CVE-2025-25257 — Fortinet FortiWeb SQL Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-25257</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-25257</guid><description>This vulnerability in Fortinet FortiWeb allows an unauthenticated attacker to inject malicious SQL code through crafted HTTP or HTTPS requests, meaning no login credentials are required to exploit it. A successful attack could allow an adversary to read, modify, or delete database contents, potentially exposing sensitive configuration data or credentials. Because FortiWeb is a web application firewall, compromise could undermine protections it provides to downstream applications.</description><pubDate>Fri, 18 Jul 2025 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiWeb</category></item><item><title>CVE-2019-6693 — Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability</title><link>https://wildfortech.com/security#CVE-2019-6693</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2019-6693</guid><description>FortiOS contains a hard-coded encryption key embedded in the product, meaning anyone who knows that key — including attackers — can decrypt sensitive data from FortiOS configuration backup files. Configuration backups typically contain credentials, network topology, and policy details, making this a serious exposure. The vulnerability has been linked to ransomware campaigns, meaning real-world threat actors are actively exploiting it to compromise enterprise network infrastructure.</description><pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiOS</category></item></channel></rss>