Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Security Flaws in Latest Update

Fortinet Addresses Critical Security Flaws in Latest Update

Posted on February 11, 2026 By CWS

Fortinet has recently released a series of security advisories addressing multiple vulnerabilities across its products. The updates, issued on Tuesday, contain crucial fixes for FortiAuthenticator, FortiClient for Windows, FortiGate, FortiOS, and FortiSandbox, including two high-severity flaws.

Details of the Most Critical Vulnerabilities

The most significant of these vulnerabilities is identified as CVE-2025-52436, an XSS vulnerability found in FortiSandbox. This flaw poses a serious risk as it allows attackers to execute commands without needing authentication by sending specially crafted requests.

Another notable issue is CVE-2026-22153, which involves an authentication bypass in FortiOS. Under certain configurations, this vulnerability can allow unauthorized access to bypass LDAP authentication, impacting Agentless VPN or FSSO policies.

Additional Flaws and Their Impact

Alongside the high-severity issues, Fortinet has also patched medium-severity vulnerabilities in FortiOS, FortiAuthenticator, FortiGate, and FortiClient for Windows. These vulnerabilities could lead to unauthorized access to sensitive information, allow HTTP request smuggling, modification of user accounts, execution of arbitrary code, and writing of arbitrary files.

Particularly concerning is CVE-2025-68686, which relates to the exposure of sensitive information in FortiOS SSL-VPN. This bug could potentially allow attackers to circumvent previous patches designed to address symbolic link persistence vulnerabilities, thereby compromising system security.

Recent Fixes and User Recommendations

Just days before these updates, Fortinet addressed a critical SQL injection vulnerability, CVE-2026-21643, which carried a CVSS score of 9.1. This flaw in FortiClientEMS could be exploited remotely, allowing for arbitrary code execution without requiring authentication.

While Fortinet has not reported any exploitation of these vulnerabilities in real-world attacks, users are strongly advised to apply the patches immediately to safeguard their systems. For more detailed information, users can refer to Fortinet’s PSIRT advisories page.

Fortinet’s proactive measures in addressing these issues highlight the importance of staying updated with security patches to mitigate potential risks and protect digital infrastructure.

Security Week News Tags:Authentication, Cybersecurity, Fortinet, FortiOS, FortiSandbox, security patch, SQL injection, SSL-VPN, Vulnerabilities, XSS

Post navigation

Previous Post: Critical Windows Shell Vulnerability Threatens User Security
Next Post: Six New Microsoft Vulnerabilities Added to CISA’s KEV List

Related Posts

Gen Z in the Crosshairs: Cybercriminals Shift Focus to Young, Digital-Savvy Workers Gen Z in the Crosshairs: Cybercriminals Shift Focus to Young, Digital-Savvy Workers Security Week News
Over 50,000 Asus Routers Hacked in ‘Operation WrtHug’ Over 50,000 Asus Routers Hacked in ‘Operation WrtHug’ Security Week News
PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins PLoB: A Behavioral Fingerprinting Framework to Hunt for Malicious Logins Security Week News
vBulletin Vulnerability Exploited in the Wild vBulletin Vulnerability Exploited in the Wild Security Week News
Automotive Titan Stellantis Discloses Data Breach Automotive Titan Stellantis Discloses Data Breach Security Week News
New Firefox Extensions Required to Disclose Data Collection Practices New Firefox Extensions Required to Disclose Data Collection Practices Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SSHStalker Botnet Utilizes IRC to Control Legacy Linux Systems
  • Microsoft Addresses Teams Assignment Issues After Update Glitch
  • Data Breach at Conduent Exposes Volvo Group Employees
  • Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed
  • Microsoft’s Critical Windows 11 Updates Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SSHStalker Botnet Utilizes IRC to Control Legacy Linux Systems
  • Microsoft Addresses Teams Assignment Issues After Update Glitch
  • Data Breach at Conduent Exposes Volvo Group Employees
  • Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed
  • Microsoft’s Critical Windows 11 Updates Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark