Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti, Fortinet, SAP Address Critical Security Flaws

Ivanti, Fortinet, SAP Address Critical Security Flaws

Posted on June 13, 2026 By CWS

Ivanti, Fortinet, and SAP have issued crucial security updates, addressing several severe vulnerabilities that pose risks of code execution and data breaches. Organizations using these technologies are advised to apply the patches without delay to mitigate potential security threats.

Fortinet’s Response to Critical Vulnerability

Fortinet has tackled a significant command injection vulnerability identified in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, designated as CVE-2026-25089 with a CVSS score of 9.1. This flaw allows unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests.

To address this, Fortinet recommends updating FortiSandbox to version 5.0.6 or higher for affected versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. FortiSandbox Cloud and PaaS users are similarly advised to upgrade to 5.0.6 or newer.

Ivanti’s Critical Security Fixes

On Tuesday, Ivanti released fixes for two critical vulnerabilities in Ivanti Sentry, previously known as MobileIron Sentry. The vulnerabilities, CVE-2026-10520 and CVE-2026-10523, carry CVSS scores of 10.0 and 9.9, respectively. These flaws could enable remote code execution and unauthorized administrative access if left unpatched.

The update enhances security by adding authentication layers, effectively blocking unauthenticated access to vulnerable endpoints. This proactive measure significantly increases the difficulty for attackers attempting to exploit these vulnerabilities.

SAP’s Security Enhancements

SAP has also released patches for critical vulnerabilities within its NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, and SAP Data Hub. The vulnerabilities, which include XML signature wrapping and memory corruption issues, have CVSS scores ranging from 9.0 to 9.9.

Exploitation of these flaws could result in unauthorized access and system disruptions. SAP advises all users to implement the latest updates to secure their systems against potential threats.

Although there is no immediate evidence of these vulnerabilities being exploited in the wild, applying these updates is deemed a best practice to ensure robust security.

Exploitation and Responses

The Shadowserver Foundation has observed attempts to exploit Ivanti Sentry’s CVE-2026-10520, with reports indicating some compromised instances. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the fixes by June 14.

Additionally, Ivanti noted that exploitation requires access to the management port, typically not exposed to the internet. Implementing multi-factor authentication and restricted access can further enhance security.

Organizations are urged to prioritize these updates to safeguard against emerging threats and maintain system integrity.

The Hacker News Tags:CISA, CVE-2026-10520, Cybersecurity, Exploitation, Fortinet, Ivanti, patch management, SAP, security updates, Vulnerabilities

Post navigation

Previous Post: GitHub’s NPM 12 Blocks Script Execution to Enhance Security
Next Post: Agentjacking Exploits AI Tools to Execute Malicious Code

Related Posts

Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager The Hacker News
Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers The Hacker News
Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users The Hacker News
Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark