Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet and Ivanti Address Critical Security Flaws

Fortinet and Ivanti Address Critical Security Flaws

Posted on May 13, 2026 By CWS

On Tuesday, Fortinet and Ivanti announced the release of critical patches aimed at fixing multiple security vulnerabilities within their product lines. The updates address a total of 18 flaws, three of which are classified as critical in terms of severity.

Fortinet’s Critical Security Fixes

Fortinet issued 11 advisories revealing several vulnerabilities, two of which are critical. The first flaw, identified as CVE-2026-44277 with a CVSS score of 9.1, is an improper access control issue in FortiAuthenticator. This vulnerability allows unauthorized remote access through specially crafted requests. Notably, FortiAuthenticator Cloud users remain unaffected.

The second critical flaw, CVE-2026-26083, also with a CVSS score of 9.1, involves a missing authorization issue in FortiSandbox, affecting both its cloud and PaaS WEB UI versions. Remote attackers could exploit this vulnerability through crafted HTTP requests, potentially enabling code or command execution.

Additionally, Fortinet addressed a high-severity out-of-bounds write vulnerability (CVE-2025-53844) in the FortiOS capwap daemon, which could lead to unauthorized code execution on FortiGate devices. This vulnerability requires an attacker to control an authenticated FortiAP, FortiExtender, or FortiSwitch.

Ivanti’s Security Updates

Ivanti released four advisories covering seven security defects across various products, including Ivanti Secure Access Client, Xtraction, Virtual Traffic Manager, and Endpoint Manager (EPM). The most severe issue, CVE-2026-8043, scored at 9.6, is an external control of file names vulnerability in Xtraction. This flaw could allow unauthorized reading of sensitive files and writing of arbitrary HTML files.

Ivanti also mitigated four high-severity vulnerabilities, which include SQL injection and incorrect permissions assignments in EPM, an OS command injection in Virtual Traffic Manager, and a race condition in Secure Access Client. These vulnerabilities pose risks of privilege escalation and remote code execution.

No Exploitation Detected

Both companies have stated that, as of now, there is no evidence that these vulnerabilities have been exploited in the wild. The swift release of patches underlines the ongoing commitment of Fortinet and Ivanti to protect their users from potential cyber threats.

In related security news, Zoom also released updates on Tuesday, addressing three security issues, including two high-severity vulnerabilities in their Rooms for Windows and Workplace VDI Plugin for Windows, which could lead to privilege escalation.

For further reading on security updates, Chipmaker Patch Tuesday reports from Intel and AMD, ICS Patch Tuesday advisories from Siemens, Schneider, and CISA, as well as Microsoft’s patch for 137 vulnerabilities, are available.

Security Week News Tags:CVE-2026-26083, CVE-2026-44277, CVE-2026-8043, Cybersecurity, Endpoint Manager, Fortinet, FortiOS, Ivanti, Secure Access Client, security patches, software updates, Virtual Traffic Manager, Vulnerabilities, Xtraction

Post navigation

Previous Post: Google Unveils AI Security Enhancements for Android

Related Posts

Swedish Truck Giant Scania Investigating Hack Swedish Truck Giant Scania Investigating Hack Security Week News
Telecom Firm Colt Confirms Data Breach as Ransomware Group Auctions Files Telecom Firm Colt Confirms Data Breach as Ransomware Group Auctions Files Security Week News
RubyGems Halts Registrations Amid Security Threat RubyGems Halts Registrations Amid Security Threat Security Week News
Data Breach Affects 250,000 at Nacogdoches Hospital Data Breach Affects 250,000 at Nacogdoches Hospital Security Week News
Korean Air Data Compromised in Oracle EBS Hack Korean Air Data Compromised in Oracle EBS Hack Security Week News
Australia Sanctions Hackers Supporting North Korea’s Weapons Program Australia Sanctions Hackers Supporting North Korea’s Weapons Program Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet and Ivanti Address Critical Security Flaws
  • Google Unveils AI Security Enhancements for Android
  • Intel and AMD Address 70 Security Weaknesses on Patch Tuesday
  • GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration
  • Critical Exim GnuTLS Flaw Exposes Servers to Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet and Ivanti Address Critical Security Flaws
  • Google Unveils AI Security Enhancements for Android
  • Intel and AMD Address 70 Security Weaknesses on Patch Tuesday
  • GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration
  • Critical Exim GnuTLS Flaw Exposes Servers to Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark