Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Security Flaws in Latest Update

Fortinet Addresses Critical Security Flaws in Latest Update

Posted on February 11, 2026 By CWS

Fortinet has recently released a series of security advisories addressing multiple vulnerabilities across its products. The updates, issued on Tuesday, contain crucial fixes for FortiAuthenticator, FortiClient for Windows, FortiGate, FortiOS, and FortiSandbox, including two high-severity flaws.

Details of the Most Critical Vulnerabilities

The most significant of these vulnerabilities is identified as CVE-2025-52436, an XSS vulnerability found in FortiSandbox. This flaw poses a serious risk as it allows attackers to execute commands without needing authentication by sending specially crafted requests.

Another notable issue is CVE-2026-22153, which involves an authentication bypass in FortiOS. Under certain configurations, this vulnerability can allow unauthorized access to bypass LDAP authentication, impacting Agentless VPN or FSSO policies.

Additional Flaws and Their Impact

Alongside the high-severity issues, Fortinet has also patched medium-severity vulnerabilities in FortiOS, FortiAuthenticator, FortiGate, and FortiClient for Windows. These vulnerabilities could lead to unauthorized access to sensitive information, allow HTTP request smuggling, modification of user accounts, execution of arbitrary code, and writing of arbitrary files.

Particularly concerning is CVE-2025-68686, which relates to the exposure of sensitive information in FortiOS SSL-VPN. This bug could potentially allow attackers to circumvent previous patches designed to address symbolic link persistence vulnerabilities, thereby compromising system security.

Recent Fixes and User Recommendations

Just days before these updates, Fortinet addressed a critical SQL injection vulnerability, CVE-2026-21643, which carried a CVSS score of 9.1. This flaw in FortiClientEMS could be exploited remotely, allowing for arbitrary code execution without requiring authentication.

While Fortinet has not reported any exploitation of these vulnerabilities in real-world attacks, users are strongly advised to apply the patches immediately to safeguard their systems. For more detailed information, users can refer to Fortinet’s PSIRT advisories page.

Fortinet’s proactive measures in addressing these issues highlight the importance of staying updated with security patches to mitigate potential risks and protect digital infrastructure.

Security Week News Tags:Authentication, Cybersecurity, Fortinet, FortiOS, FortiSandbox, security patch, SQL injection, SSL-VPN, Vulnerabilities, XSS

Post navigation

Previous Post: Critical Windows Shell Vulnerability Threatens User Security
Next Post: Six New Microsoft Vulnerabilities Added to CISA’s KEV List

Related Posts

In Other News: Microsoft Probes ToolShell Leak, Port Cybersecurity, Raspberry Pi ATM Hack In Other News: Microsoft Probes ToolShell Leak, Port Cybersecurity, Raspberry Pi ATM Hack Security Week News
SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover Security Week News
US Posts  Million Bounty for Iranian Hackers US Posts $10 Million Bounty for Iranian Hackers Security Week News
Iranian Drone Attacks Expose Data Center Vulnerabilities Iranian Drone Attacks Expose Data Center Vulnerabilities Security Week News
Russian APT Hits Ukrainian Government With New Malware via Signal Russian APT Hits Ukrainian Government With New Malware via Signal Security Week News
Researchers Expose WHILL Wheelchair Safety Risks via Remote Hacking Researchers Expose WHILL Wheelchair Safety Risks via Remote Hacking Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark