Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Vulnerabilities in Key Products

Fortinet Addresses Critical Vulnerabilities in Key Products

Posted on May 12, 2026 By CWS

On May 12, 2026, Fortinet announced crucial security updates addressing five vulnerabilities in a range of its products, including wireless access point controllers, network operating systems, and enterprise management platforms. Among these, a critical flaw was identified in FortiSandbox, posing significant security risks.

Key Vulnerability in FortiSandbox

The most concerning vulnerability, tagged as CVE-2026-26083 (FG-IR-26-136), is a missing authorization flaw affecting FortiSandbox, including its Cloud and PaaS versions. This critical GUI-accessible flaw allows remote attackers to bypass authentication and access sensitive data without credentials. Versions impacted include FortiSandbox 5.0 and 4.4, FortiSandbox Cloud 24, 23, and 5.0, and FortiSandbox PaaS from 22.1 to 23.4. Due to its severity, addressing this flaw is a top priority for organizations using these products.

Command Injection Flaws in FortiAP

Fortinet also disclosed two medium-severity OS command injection vulnerabilities in its FortiAP firmware. CVE-2025-53680 (FG-IR-26-131) and CVE-2025-53870 (FG-IR-26-133) impact various FortiAP and FortiAP-W2 versions, requiring authenticated internal access to exploit. Attackers with CLI access could execute arbitrary OS-level commands, necessitating immediate attention to mitigate potential threats.

Additional Vulnerabilities and Their Impact

CVE-2025-67604 (FG-IR-26-137) poses a medium threat due to a dangerous function vulnerability in the API layer of FortiAnalyzer and FortiManager. Affecting versions 7.0 through 8.0, this flaw could enable an internal attacker to trigger denial-of-service conditions, impacting crucial enterprise operations. Similarly, CVE-2025-53844 (FG-IR-26-123), an out-of-bounds write vulnerability in FortiOS, could allow attackers to disrupt FortiOS processes via malformed CAPWAP traffic.

Organizations are urged to prioritize patching CVE-2026-26083 due to its critical nature and unauthenticated attack surface. For medium-severity issues, it’s recommended to apply patches during scheduled maintenance, restrict CLI and API access, and closely monitor network traffic for irregular activities.

For detailed patch information and recommended workarounds, Fortinet’s PSIRT advisory page remains the best resource. Stay informed by following Fortinet on Google News, LinkedIn, and X for the latest updates.

Cyber Security News Tags:Cybersecurity, enterprise management, FortiAnalyzer, FortiAP, FortiManager, Fortinet, FortiOS, FortiSandbox, IT security, network security, patch update, security updates, threat protection, unauthorized access, Vulnerabilities

Post navigation

Previous Post: Exaforce Secures $125M to Advance AI-Driven SOC Platform
Next Post: Hackers Agree to Erase Data Stolen From Canvas Platform

Related Posts

NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools Cyber Security News
Cyber Startup Frenetik Launches Patented Deception Technology to Counter the AI Arms Race Cyber Startup Frenetik Launches Patented Deception Technology to Counter the AI Arms Race Cyber Security News
Microsoft Fixes Vulnerability in Entra Agent ID Administration Microsoft Fixes Vulnerability in Entra Agent ID Administration Cyber Security News
Unencrypted TPMS in Major Cars Pose Privacy Risks Unencrypted TPMS in Major Cars Pose Privacy Risks Cyber Security News
Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details Hackers Leverage Malicious PyPI Package to Attack Users and Steal Cryptocurrency Details Cyber Security News
Russia’s Use of Cellebrite to Access Activist’s iPhone Russia’s Use of Cellebrite to Access Activist’s iPhone Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kosovo National Admits Guilt in Rydox Cybercrime Case
  • File Notification Systems Leak User Data on Major OS
  • Bitget Loses $351.6M in Hacker Breach, Suspects North Korea
  • Ethereum Bridge Exploit Drains Payy Network Funds
  • Roundcube Vulnerability Exploitation Alert: SQL Injection Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kosovo National Admits Guilt in Rydox Cybercrime Case
  • File Notification Systems Leak User Data on Major OS
  • Bitget Loses $351.6M in Hacker Breach, Suspects North Korea
  • Ethereum Bridge Exploit Drains Payy Network Funds
  • Roundcube Vulnerability Exploitation Alert: SQL Injection Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark