Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Patches Critical Vulnerabilities in Key Products

Fortinet Patches Critical Vulnerabilities in Key Products

Posted on March 10, 2026 By CWS

Fortinet has issued a comprehensive security alert on March 10, 2026, addressing a series of vulnerabilities found in its principal enterprise software, namely FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox. These vulnerabilities, which include authentication bypasses, buffer overflows, OS command injection, and SQL injection, pose significant risk as they could be exploited by remote attackers to execute unauthorized commands or escalate privileges on compromised systems.

High-Severity Vulnerabilities

Among the identified vulnerabilities, two have been classified with a High severity rating, representing the greatest threat to systems that have not been patched. CVE-2026-22627, a Classic Buffer Overflow in the LLDP OUI field of FortiSwitchAXFixed versions 1.0.0 and 1.0.1, may enable attackers to execute arbitrary code by overwriting adjacent memory. Another critical issue, CVE-2025-54820, involves a Stack-based Buffer Overflow in the FortiManager fgtupdates service, affecting versions 7.4.0 through 7.4.2 and 7.2.9 through 7.2.10. This flaw could lead to remote code execution if exploited through a crafted update request.

Authentication Bypass Risks

Three vulnerabilities have been discovered that compromise authentication across FortiManager and FortiAnalyzer, posing significant access control threats. CVE-2026-22629 highlights an improper restriction of excessive authentication attempts in FortiAnalyzer and FortiManager versions 7.6.0–7.6.4, allowing attackers to bypass lockouts via a race condition. CVE-2026-22572 allows an authentication bypass using an alternate path or channel in the GUI, affecting similar versions and enabling attackers to circumvent multi-factor authentication. Additionally, CVE-2025-68482 exposes improper TLS certificate validation during SSO authentication, potentially allowing interception via a man-in-the-middle attack.

Command Injection and Privilege Escalation Threats

CVE-2026-25836 is an OS Command Injection vulnerability in the vmimages update feature of FortiSandbox Cloud 5.0.4, which might allow authenticated attackers to run arbitrary OS commands through the GUI. CVE-2025-48418 reveals an undocumented CLI feature in FortiManager and FortiAnalyzer versions 7.6.0–7.6.3 that could be exploited to escalate privileges. Another issue, CVE-2026-22628, notes improper access control in FortiSwitchAXFixed, allowing admin users to bypass command restrictions via SSH.

In addition to these, the advisory includes several medium-rated vulnerabilities, such as a format string vulnerability in the fazsvcd component and an SQL Injection flaw in the FortiAnalyzer JSON-RPC API.

Recommended Actions

Organizations using impacted Fortinet products should immediately apply the released patches, especially focusing on the high-severity buffer overflow issues. It is crucial to audit administrative access and verify MFA configurations on FortiManager and FortiAnalyzer. Limiting CLI and SSH access to trusted admins and monitoring for unusual behaviors in logs are also advised steps. FortiSandbox Cloud environments should be reviewed for any command injection attempts. Fortinet’s full technical advisories are available through the FortiGuard PSIRT portal, and administrators are encouraged to verify their installed versions against the affected lists.

Stay updated with the latest cybersecurity news by following us on Google News, LinkedIn, and X. Contact us to share your stories.

Cyber Security News Tags:authentication bypass, buffer overflow, command injection, CVE, Cybersecurity, FortiAnalyzer, FortiManager, Fortinet, FortiSandbox, FortiSwitch, network security, privilege escalation, security patch, software update, Vulnerabilities

Post navigation

Previous Post: Microsoft Addresses 83 Security Vulnerabilities in March Update
Next Post: Adobe Addresses 80 Security Flaws in Multiple Software

Related Posts

Microsoft Unveils New Tool to Migrate VMware Virtual Machines From vCenter to Hyper-V Microsoft Unveils New Tool to Migrate VMware Virtual Machines From vCenter to Hyper-V Cyber Security News
Airlock Digital Introduces AI Control for Enhanced Security Airlock Digital Introduces AI Control for Enhanced Security Cyber Security News
20 Best SNMP Monitoring Tools in 2025 20 Best SNMP Monitoring Tools in 2025 Cyber Security News
Enhance SOC Visibility to Reduce MTTR Effectively Enhance SOC Visibility to Reduce MTTR Effectively Cyber Security News
Pioneering AI Cyberattack Exploits Zero-Day Vulnerabilities Pioneering AI Cyberattack Exploits Zero-Day Vulnerabilities Cyber Security News
D-Link Router Security Flaws: Update Now to Protect Credentials D-Link Router Security Flaws: Update Now to Protect Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark