Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti, Fortinet, SAP Address Critical Security Flaws

Ivanti, Fortinet, SAP Address Critical Security Flaws

Posted on June 13, 2026 By CWS

Ivanti, Fortinet, and SAP have issued crucial security updates, addressing several severe vulnerabilities that pose risks of code execution and data breaches. Organizations using these technologies are advised to apply the patches without delay to mitigate potential security threats.

Fortinet’s Response to Critical Vulnerability

Fortinet has tackled a significant command injection vulnerability identified in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, designated as CVE-2026-25089 with a CVSS score of 9.1. This flaw allows unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests.

To address this, Fortinet recommends updating FortiSandbox to version 5.0.6 or higher for affected versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. FortiSandbox Cloud and PaaS users are similarly advised to upgrade to 5.0.6 or newer.

Ivanti’s Critical Security Fixes

On Tuesday, Ivanti released fixes for two critical vulnerabilities in Ivanti Sentry, previously known as MobileIron Sentry. The vulnerabilities, CVE-2026-10520 and CVE-2026-10523, carry CVSS scores of 10.0 and 9.9, respectively. These flaws could enable remote code execution and unauthorized administrative access if left unpatched.

The update enhances security by adding authentication layers, effectively blocking unauthenticated access to vulnerable endpoints. This proactive measure significantly increases the difficulty for attackers attempting to exploit these vulnerabilities.

SAP’s Security Enhancements

SAP has also released patches for critical vulnerabilities within its NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, and SAP Data Hub. The vulnerabilities, which include XML signature wrapping and memory corruption issues, have CVSS scores ranging from 9.0 to 9.9.

Exploitation of these flaws could result in unauthorized access and system disruptions. SAP advises all users to implement the latest updates to secure their systems against potential threats.

Although there is no immediate evidence of these vulnerabilities being exploited in the wild, applying these updates is deemed a best practice to ensure robust security.

Exploitation and Responses

The Shadowserver Foundation has observed attempts to exploit Ivanti Sentry’s CVE-2026-10520, with reports indicating some compromised instances. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the fixes by June 14.

Additionally, Ivanti noted that exploitation requires access to the management port, typically not exposed to the internet. Implementing multi-factor authentication and restricted access can further enhance security.

Organizations are urged to prioritize these updates to safeguard against emerging threats and maintain system integrity.

The Hacker News Tags:CISA, CVE-2026-10520, Cybersecurity, Exploitation, Fortinet, Ivanti, patch management, SAP, security updates, Vulnerabilities

Post navigation

Previous Post: GitHub’s NPM 12 Blocks Script Execution to Enhance Security
Next Post: Agentjacking Exploits AI Tools to Execute Malicious Code

Related Posts

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice The Hacker News
VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption The Hacker News
TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution The Hacker News
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup The Hacker News
Malicious Go Module Targets Passwords and Installs Backdoor Malicious Go Module Targets Passwords and Installs Backdoor The Hacker News
Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Cisco, Chrome, Arista Security Flaws
  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Cisco, Chrome, Arista Security Flaws
  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark