Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Vulnerabilities in Key Products

Fortinet Addresses Critical Vulnerabilities in Key Products

Posted on May 12, 2026 By CWS

On May 12, 2026, Fortinet announced crucial security updates addressing five vulnerabilities in a range of its products, including wireless access point controllers, network operating systems, and enterprise management platforms. Among these, a critical flaw was identified in FortiSandbox, posing significant security risks.

Key Vulnerability in FortiSandbox

The most concerning vulnerability, tagged as CVE-2026-26083 (FG-IR-26-136), is a missing authorization flaw affecting FortiSandbox, including its Cloud and PaaS versions. This critical GUI-accessible flaw allows remote attackers to bypass authentication and access sensitive data without credentials. Versions impacted include FortiSandbox 5.0 and 4.4, FortiSandbox Cloud 24, 23, and 5.0, and FortiSandbox PaaS from 22.1 to 23.4. Due to its severity, addressing this flaw is a top priority for organizations using these products.

Command Injection Flaws in FortiAP

Fortinet also disclosed two medium-severity OS command injection vulnerabilities in its FortiAP firmware. CVE-2025-53680 (FG-IR-26-131) and CVE-2025-53870 (FG-IR-26-133) impact various FortiAP and FortiAP-W2 versions, requiring authenticated internal access to exploit. Attackers with CLI access could execute arbitrary OS-level commands, necessitating immediate attention to mitigate potential threats.

Additional Vulnerabilities and Their Impact

CVE-2025-67604 (FG-IR-26-137) poses a medium threat due to a dangerous function vulnerability in the API layer of FortiAnalyzer and FortiManager. Affecting versions 7.0 through 8.0, this flaw could enable an internal attacker to trigger denial-of-service conditions, impacting crucial enterprise operations. Similarly, CVE-2025-53844 (FG-IR-26-123), an out-of-bounds write vulnerability in FortiOS, could allow attackers to disrupt FortiOS processes via malformed CAPWAP traffic.

Organizations are urged to prioritize patching CVE-2026-26083 due to its critical nature and unauthenticated attack surface. For medium-severity issues, it’s recommended to apply patches during scheduled maintenance, restrict CLI and API access, and closely monitor network traffic for irregular activities.

For detailed patch information and recommended workarounds, Fortinet’s PSIRT advisory page remains the best resource. Stay informed by following Fortinet on Google News, LinkedIn, and X for the latest updates.

Cyber Security News Tags:Cybersecurity, enterprise management, FortiAnalyzer, FortiAP, FortiManager, Fortinet, FortiOS, FortiSandbox, IT security, network security, patch update, security updates, threat protection, unauthorized access, Vulnerabilities

Post navigation

Previous Post: Exaforce Secures $125M to Advance AI-Driven SOC Platform
Next Post: Hackers Agree to Erase Data Stolen From Canvas Platform

Related Posts

Cybersecurity News Recap – Chrome, Gemini Vulnerabilities, Linux Malware, and Man-in-the-Prompt Attack Cybersecurity News Recap – Chrome, Gemini Vulnerabilities, Linux Malware, and Man-in-the-Prompt Attack Cyber Security News
Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs Hackers Exploit RTL/LTR Scripts and Browser Gaps to Hide Malicious URLs Cyber Security News
How ShinyHunters Breached Google, Adidas, Louis Vuitton and More in Salesforce Attack Campaign How ShinyHunters Breached Google, Adidas, Louis Vuitton and More in Salesforce Attack Campaign Cyber Security News
Cyberattack Targets South Asian Financial Firm with Custom Malware Cyberattack Targets South Asian Financial Firm with Custom Malware Cyber Security News
AWS Sandbox Vulnerability Exposes Data to Covert Channels AWS Sandbox Vulnerability Exposes Data to Covert Channels Cyber Security News
Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources Linux Kernel’s KSMBD Subsystem Vulnerability Let Remote Attackers Exhaust Server Resources Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Agree to Erase Data Stolen From Canvas Platform
  • Fortinet Addresses Critical Vulnerabilities in Key Products
  • Exaforce Secures $125M to Advance AI-Driven SOC Platform
  • May 2026 Microsoft Patch Tuesday Fixes 120 Vulnerabilities
  • Microsoft Addresses 137 Security Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Agree to Erase Data Stolen From Canvas Platform
  • Fortinet Addresses Critical Vulnerabilities in Key Products
  • Exaforce Secures $125M to Advance AI-Driven SOC Platform
  • May 2026 Microsoft Patch Tuesday Fixes 120 Vulnerabilities
  • Microsoft Addresses 137 Security Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark