Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti, Fortinet, SAP Address Critical Security Flaws

Ivanti, Fortinet, SAP Address Critical Security Flaws

Posted on June 13, 2026 By CWS

Ivanti, Fortinet, and SAP have issued crucial security updates, addressing several severe vulnerabilities that pose risks of code execution and data breaches. Organizations using these technologies are advised to apply the patches without delay to mitigate potential security threats.

Fortinet’s Response to Critical Vulnerability

Fortinet has tackled a significant command injection vulnerability identified in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, designated as CVE-2026-25089 with a CVSS score of 9.1. This flaw allows unauthenticated attackers to execute arbitrary commands via specially crafted HTTP requests.

To address this, Fortinet recommends updating FortiSandbox to version 5.0.6 or higher for affected versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. FortiSandbox Cloud and PaaS users are similarly advised to upgrade to 5.0.6 or newer.

Ivanti’s Critical Security Fixes

On Tuesday, Ivanti released fixes for two critical vulnerabilities in Ivanti Sentry, previously known as MobileIron Sentry. The vulnerabilities, CVE-2026-10520 and CVE-2026-10523, carry CVSS scores of 10.0 and 9.9, respectively. These flaws could enable remote code execution and unauthorized administrative access if left unpatched.

The update enhances security by adding authentication layers, effectively blocking unauthenticated access to vulnerable endpoints. This proactive measure significantly increases the difficulty for attackers attempting to exploit these vulnerabilities.

SAP’s Security Enhancements

SAP has also released patches for critical vulnerabilities within its NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, and SAP Data Hub. The vulnerabilities, which include XML signature wrapping and memory corruption issues, have CVSS scores ranging from 9.0 to 9.9.

Exploitation of these flaws could result in unauthorized access and system disruptions. SAP advises all users to implement the latest updates to secure their systems against potential threats.

Although there is no immediate evidence of these vulnerabilities being exploited in the wild, applying these updates is deemed a best practice to ensure robust security.

Exploitation and Responses

The Shadowserver Foundation has observed attempts to exploit Ivanti Sentry’s CVE-2026-10520, with reports indicating some compromised instances. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the fixes by June 14.

Additionally, Ivanti noted that exploitation requires access to the management port, typically not exposed to the internet. Implementing multi-factor authentication and restricted access can further enhance security.

Organizations are urged to prioritize these updates to safeguard against emerging threats and maintain system integrity.

The Hacker News Tags:CISA, CVE-2026-10520, Cybersecurity, Exploitation, Fortinet, Ivanti, patch management, SAP, security updates, Vulnerabilities

Post navigation

Previous Post: GitHub’s NPM 12 Blocks Script Execution to Enhance Security
Next Post: Agentjacking Exploits AI Tools to Execute Malicious Code

Related Posts

Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation The Hacker News
Managing Shadow AI Tools Efficiently in the Workplace Managing Shadow AI Tools Efficiently in the Workplace The Hacker News
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds The Hacker News
NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft The Hacker News
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors The Hacker News
GPUBreach Exploit Elevates CPU Privileges via GPU Memory GPUBreach Exploit Elevates CPU Privileges via GPU Memory The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leading Phishing Kits Exploit Microsoft 365 in Cyberattacks
  • Critical Security Update for JetBrains TeamCity Users
  • AI Uncovers Cryptographic Flaws Overlooked by Experts
  • Claude AI Unveils Breakthrough in Cryptanalysis
  • Google Ads Misused to Spread MacSync Infostealer via Fake Claude Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark