Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Patches Critical Vulnerabilities in Key Products

Fortinet Patches Critical Vulnerabilities in Key Products

Posted on March 10, 2026 By CWS

Fortinet has issued a comprehensive security alert on March 10, 2026, addressing a series of vulnerabilities found in its principal enterprise software, namely FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox. These vulnerabilities, which include authentication bypasses, buffer overflows, OS command injection, and SQL injection, pose significant risk as they could be exploited by remote attackers to execute unauthorized commands or escalate privileges on compromised systems.

High-Severity Vulnerabilities

Among the identified vulnerabilities, two have been classified with a High severity rating, representing the greatest threat to systems that have not been patched. CVE-2026-22627, a Classic Buffer Overflow in the LLDP OUI field of FortiSwitchAXFixed versions 1.0.0 and 1.0.1, may enable attackers to execute arbitrary code by overwriting adjacent memory. Another critical issue, CVE-2025-54820, involves a Stack-based Buffer Overflow in the FortiManager fgtupdates service, affecting versions 7.4.0 through 7.4.2 and 7.2.9 through 7.2.10. This flaw could lead to remote code execution if exploited through a crafted update request.

Authentication Bypass Risks

Three vulnerabilities have been discovered that compromise authentication across FortiManager and FortiAnalyzer, posing significant access control threats. CVE-2026-22629 highlights an improper restriction of excessive authentication attempts in FortiAnalyzer and FortiManager versions 7.6.0–7.6.4, allowing attackers to bypass lockouts via a race condition. CVE-2026-22572 allows an authentication bypass using an alternate path or channel in the GUI, affecting similar versions and enabling attackers to circumvent multi-factor authentication. Additionally, CVE-2025-68482 exposes improper TLS certificate validation during SSO authentication, potentially allowing interception via a man-in-the-middle attack.

Command Injection and Privilege Escalation Threats

CVE-2026-25836 is an OS Command Injection vulnerability in the vmimages update feature of FortiSandbox Cloud 5.0.4, which might allow authenticated attackers to run arbitrary OS commands through the GUI. CVE-2025-48418 reveals an undocumented CLI feature in FortiManager and FortiAnalyzer versions 7.6.0–7.6.3 that could be exploited to escalate privileges. Another issue, CVE-2026-22628, notes improper access control in FortiSwitchAXFixed, allowing admin users to bypass command restrictions via SSH.

In addition to these, the advisory includes several medium-rated vulnerabilities, such as a format string vulnerability in the fazsvcd component and an SQL Injection flaw in the FortiAnalyzer JSON-RPC API.

Recommended Actions

Organizations using impacted Fortinet products should immediately apply the released patches, especially focusing on the high-severity buffer overflow issues. It is crucial to audit administrative access and verify MFA configurations on FortiManager and FortiAnalyzer. Limiting CLI and SSH access to trusted admins and monitoring for unusual behaviors in logs are also advised steps. FortiSandbox Cloud environments should be reviewed for any command injection attempts. Fortinet’s full technical advisories are available through the FortiGuard PSIRT portal, and administrators are encouraged to verify their installed versions against the affected lists.

Stay updated with the latest cybersecurity news by following us on Google News, LinkedIn, and X. Contact us to share your stories.

Cyber Security News Tags:authentication bypass, buffer overflow, command injection, CVE, Cybersecurity, FortiAnalyzer, FortiManager, Fortinet, FortiSandbox, FortiSwitch, network security, privilege escalation, security patch, software update, Vulnerabilities

Post navigation

Previous Post: Microsoft Addresses 83 Security Vulnerabilities in March Update
Next Post: Adobe Addresses 80 Security Flaws in Multiple Software

Related Posts

Microsoft Releases Update for Windows 11, version 25H2 and 24H2 Systems Microsoft Releases Update for Windows 11, version 25H2 and 24H2 Systems Cyber Security News
Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server Cyber Security News
Russian and North Korean Hackers Form Alliances to Attack Organizations Worldwide Russian and North Korean Hackers Form Alliances to Attack Organizations Worldwide Cyber Security News
Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware Chinese Threat Actors Using 2,800 Malicious Domains to Deliver Windows-Specific Malware Cyber Security News
OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently Cyber Security News
CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet FortiManager Flaw Risks Unauthorized Command Execution
  • Ericsson Data Breach Exposes Thousands’ Information
  • Critical Zoom Vulnerabilities in Windows Prompt Immediate Updates
  • Adobe Addresses 80 Security Flaws in Multiple Software
  • Fortinet Patches Critical Vulnerabilities in Key Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet FortiManager Flaw Risks Unauthorized Command Execution
  • Ericsson Data Breach Exposes Thousands’ Information
  • Critical Zoom Vulnerabilities in Windows Prompt Immediate Updates
  • Adobe Addresses 80 Security Flaws in Multiple Software
  • Fortinet Patches Critical Vulnerabilities in Key Products

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News