Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Addresses Critical Vulnerabilities in Key Products

Fortinet Addresses Critical Vulnerabilities in Key Products

Posted on May 12, 2026 By CWS

On May 12, 2026, Fortinet announced crucial security updates addressing five vulnerabilities in a range of its products, including wireless access point controllers, network operating systems, and enterprise management platforms. Among these, a critical flaw was identified in FortiSandbox, posing significant security risks.

Key Vulnerability in FortiSandbox

The most concerning vulnerability, tagged as CVE-2026-26083 (FG-IR-26-136), is a missing authorization flaw affecting FortiSandbox, including its Cloud and PaaS versions. This critical GUI-accessible flaw allows remote attackers to bypass authentication and access sensitive data without credentials. Versions impacted include FortiSandbox 5.0 and 4.4, FortiSandbox Cloud 24, 23, and 5.0, and FortiSandbox PaaS from 22.1 to 23.4. Due to its severity, addressing this flaw is a top priority for organizations using these products.

Command Injection Flaws in FortiAP

Fortinet also disclosed two medium-severity OS command injection vulnerabilities in its FortiAP firmware. CVE-2025-53680 (FG-IR-26-131) and CVE-2025-53870 (FG-IR-26-133) impact various FortiAP and FortiAP-W2 versions, requiring authenticated internal access to exploit. Attackers with CLI access could execute arbitrary OS-level commands, necessitating immediate attention to mitigate potential threats.

Additional Vulnerabilities and Their Impact

CVE-2025-67604 (FG-IR-26-137) poses a medium threat due to a dangerous function vulnerability in the API layer of FortiAnalyzer and FortiManager. Affecting versions 7.0 through 8.0, this flaw could enable an internal attacker to trigger denial-of-service conditions, impacting crucial enterprise operations. Similarly, CVE-2025-53844 (FG-IR-26-123), an out-of-bounds write vulnerability in FortiOS, could allow attackers to disrupt FortiOS processes via malformed CAPWAP traffic.

Organizations are urged to prioritize patching CVE-2026-26083 due to its critical nature and unauthenticated attack surface. For medium-severity issues, it’s recommended to apply patches during scheduled maintenance, restrict CLI and API access, and closely monitor network traffic for irregular activities.

For detailed patch information and recommended workarounds, Fortinet’s PSIRT advisory page remains the best resource. Stay informed by following Fortinet on Google News, LinkedIn, and X for the latest updates.

Cyber Security News Tags:Cybersecurity, enterprise management, FortiAnalyzer, FortiAP, FortiManager, Fortinet, FortiOS, FortiSandbox, IT security, network security, patch update, security updates, threat protection, unauthorized access, Vulnerabilities

Post navigation

Previous Post: Exaforce Secures $125M to Advance AI-Driven SOC Platform
Next Post: Hackers Agree to Erase Data Stolen From Canvas Platform

Related Posts

New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks Cyber Security News
Apple, Google and Samsung May Enable Always-On GPS in India Apple, Google and Samsung May Enable Always-On GPS in India Cyber Security News
Network Security Checklist – 2026 Network Security Checklist – 2026 Cyber Security News
PureRAT Malware Utilizes PNG Files for Stealthy Attacks PureRAT Malware Utilizes PNG Files for Stealthy Attacks Cyber Security News
Google Enhances Chrome Security with Device-Bound Sessions Google Enhances Chrome Security with Device-Bound Sessions Cyber Security News
7 Best Security Awareness Training Platforms For MSPs in 2026 7 Best Security Awareness Training Platforms For MSPs in 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Claude Mythos 5 Redeployed to Protect US Infrastructure
  • FBI Alerts on Russian Hackers Targeting Signal Keys
  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Claude Mythos 5 Redeployed to Protect US Infrastructure
  • FBI Alerts on Russian Hackers Targeting Signal Keys
  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark