Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti, Fortinet, SAP Address Critical Security Flaws

Ivanti, Fortinet, SAP Address Critical Security Flaws

Posted on June 13, 2026 By CWS

Ivanti, Fortinet, and SAP have issued crucial security updates, addressing several severe vulnerabilities that pose risks of code execution and data breaches. Organizations using these technologies are advised to apply the patches without delay to mitigate potential security threats.

Fortinet’s Response to Critical Vulnerability

Fortinet has tackled a significant command injection vulnerability identified in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, designated as CVE-2026-25089 with a CVSS score of 9.1. This flaw allows unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests.

To address this, Fortinet recommends updating FortiSandbox to version 5.0.6 or higher for affected versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. FortiSandbox Cloud and PaaS users are similarly advised to upgrade to 5.0.6 or newer.

Ivanti’s Critical Security Fixes

On Tuesday, Ivanti released fixes for two critical vulnerabilities in Ivanti Sentry, previously known as MobileIron Sentry. The vulnerabilities, CVE-2026-10520 and CVE-2026-10523, carry CVSS scores of 10.0 and 9.9, respectively. These flaws could enable remote code execution and unauthorized administrative access if left unpatched.

The update enhances security by adding authentication layers, effectively blocking unauthenticated access to vulnerable endpoints. This proactive measure significantly increases the difficulty for attackers attempting to exploit these vulnerabilities.

SAP’s Security Enhancements

SAP has also released patches for critical vulnerabilities within its NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, and SAP Data Hub. The vulnerabilities, which include XML signature wrapping and memory corruption issues, have CVSS scores ranging from 9.0 to 9.9.

Exploitation of these flaws could result in unauthorized access and system disruptions. SAP advises all users to implement the latest updates to secure their systems against potential threats.

Although there is no immediate evidence of these vulnerabilities being exploited in the wild, applying these updates is deemed a best practice to ensure robust security.

Exploitation and Responses

The Shadowserver Foundation has observed attempts to exploit Ivanti Sentry’s CVE-2026-10520, with reports indicating some compromised instances. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the fixes by June 14.

Additionally, Ivanti noted that exploitation requires access to the management port, typically not exposed to the internet. Implementing multi-factor authentication and restricted access can further enhance security.

Organizations are urged to prioritize these updates to safeguard against emerging threats and maintain system integrity.

The Hacker News Tags:CISA, CVE-2026-10520, Cybersecurity, Exploitation, Fortinet, Ivanti, patch management, SAP, security updates, Vulnerabilities

Post navigation

Previous Post: GitHub’s NPM 12 Blocks Script Execution to Enhance Security
Next Post: Agentjacking Exploits AI Tools to Execute Malicious Code

Related Posts

BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware The Hacker News
Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks The Hacker News
Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents The Hacker News
Password Reuse in Disguise: An Often-Missed Risky Workaround Password Reuse in Disguise: An Often-Missed Risky Workaround The Hacker News
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code Execution The Hacker News
Vulnerability in Claude Extension Exposes Users to XSS Attacks Vulnerability in Claude Extension Exposes Users to XSS Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ransomware Negotiator Sentenced for BlackCat Involvement
  • Dormant GitHub Accounts Exploited for Source Code Recon
  • Sophisticated GigaWiper Malware Threatens System Security
  • Crypto Wallet Flaw ‘Ill Bloom’ Leads to $3.1 Million Theft
  • NuGet Package Threatens Payment Systems with Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ransomware Negotiator Sentenced for BlackCat Involvement
  • Dormant GitHub Accounts Exploited for Source Code Recon
  • Sophisticated GigaWiper Malware Threatens System Security
  • Crypto Wallet Flaw ‘Ill Bloom’ Leads to $3.1 Million Theft
  • NuGet Package Threatens Payment Systems with Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark