HomeUpdatesFortinet fixes vulnerabilities in key products

Fortinet patches vulnerabilities in key products

Fortinet has published an extensive security advisory , disclosing a total of eleven vulnerabilities affecting its core enterprise products. The vulnerabilities are found in platforms such as FortiManager, FortiAnalyzer, FortiSwitchAXFixed and FortiSandbox , which are widely used by enterprises to manage and protect corporate networks .

Fortinet

According to the announcement, the vulnerabilities include a wide range of technical issues, such as buffer overflows, authentication bypasses, OS command injection, and SQL injection. In several cases, a remote attacker could exploit these vulnerabilities to execute arbitrary code or gain elevated access privileges on sensitive systems.

This development is of particular concern in the cybersecurity field, as Fortinet products are used in critical infrastructure, corporate data centers, and network management environments worldwide.

See also: Warning! Serious vulnerabilities in HPE Aruba CX switches

Fortinet: High-severity vulnerabilities that require immediate attention

Among the eleven security issues identified, two stand out due to their high severity rating and potential for immediate exploitation on unpatched systems.

The first vulnerability, codenamed CVE-2026-22627, concerns a classic Buffer Overflow in the LLDP OUI field of FortiSwitchAXFixed in versions 1.0.0 and 1.0.1. In such attacks, an attacker can overwrite adjacent memory on the device, which may lead to the execution of malicious code.

The second critical vulnerability, CVE-2025-54820 , affects the FortiManager fgtupdates update service . The issue is found in versions 7.4.0 to 7.4.2 and 7.2.9 to 7.2.10 . Through specially crafted update requests, an attacker could trigger remote code execution , making the issue particularly critical for organizations that use centralized network management.

Fortinet patches vulnerabilities in key products

Security gaps in authentication and MFA mechanisms

In addition to memory vulnerabilities, Fortinet also identified several issues related to mechanisms authentication in FortiManager and FortiAnalyzer.

One of the most notable cases is CVE-2026-22629, which concerns improper restriction of repeated login attempts. The issue creates a “race condition,” allowing an attacker to make massive login attempts without triggering the account lockout mechanism. This affects FortiAnalyzer versions 7.6.0–7.6.4, FortiAnalyzer Cloud, FortiManager 7.6.0–7.6.4, and FortiManager Cloud.

See also: New “LeakyLooker” vulnerabilities in Google Looker Studio

Even more concerning is the vulnerability CVE-2026-22572, which allows authentication multi-factor (MFA) via alternative paths in the GUI of FortiAnalyzer and FortiManager versions 7.6.0–7.6.3. Since MFA is a key layer of defense for system administrators, this vulnerability can drastically reduce the effectiveness of security mechanisms.

Meanwhile, CVE-2025-68482 concerns insufficient validation of TLS certificates during the SSO authentication process. In such scenarios, an attacker could perform a man-in-the-middleby interfering with or tampering with the authentication process.

Command Injection and possible privilege escalation

CVE-2026-25836 vulnerability in FortiSandbox Cloud allows an authenticated user to execute arbitrary commands via the vmimages update function .

CVE -2025-48418 exposes an undocumented CLI feature in FortiManager and FortiAnalyzer, which could be used to escalate privileges beyond the permitted access level. It affects versions 7.6.0–7.6.3 and related cloud platforms.

Also notable is the CVE-2026-22628 in FortiSwitchAXFixed, which allows bypassing shell restrictions via specific SSH configurations.

Fortinet patches vulnerabilities in key products

Medium severity vulnerabilities and additional risks

The advisory also includes several medium severity vulnerabilities. These include CVE-2025-49784, which concerns SQL injection in the FortiAnalyzer JSON-RPC API, and CVE-2025-68648, a format string vulnerability in the fazsvcd component.

Finally, CVE-2025-53608 , a Cross-Site Scripting (XSS) vulnerability in the LDAP server option of FortiSandbox (versions 4.4.6–5.0.2), was disclosed.

See also: CISA: SolarWinds, Ivanti and Workspace One vulnerabilities on KEV list

Security recommendations for organizations and administrators

Experts recommend that organizations using Fortinet products immediately install available security updates.

In addition, it is recommended to check administrator privileges , verify MFA settings, and restrict CLI and SSH access to trusted accounts only. Continuously monitoring logs for unusual login attempts or privilege escalation activities can also help detect potential attacks early.

Fortinet has published full technical details via the FortiGuard PSIRT, urging system administrators to immediately review installed software versions and implement the necessary protection measures. In an era where cyberattacks are constantly increasing, timely updating of systems remains one of the most important lines of defense for any organization.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS