CVE-2025-68686 [KRİTİK] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 gün önce CVE-2024-1086 USN-7001-1: Linux çekirdeği kritik güvenlik güncellemesi · 1 hafta önce Proxmox Virtual Environment - Security Advisories · 1 hafta önce CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 hafta önce CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 hafta önce CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 hafta önce CVE-2026-45695 [KRİTİK] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 hafta önce Plesk Obsidian 18.0.x güvenlik mikro-güncellemeleri yayınlandı · 1 hafta önce CVE-2026-39808 [KRİTİK] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2026-25089 [KRİTİK] CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2025-68686 [KRİTİK] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 gün önce CVE-2024-1086 USN-7001-1: Linux çekirdeği kritik güvenlik güncellemesi · 1 hafta önce Proxmox Virtual Environment - Security Advisories · 1 hafta önce CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 hafta önce CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 hafta önce CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 hafta önce CVE-2026-45695 [KRİTİK] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 hafta önce Plesk Obsidian 18.0.x güvenlik mikro-güncellemeleri yayınlandı · 1 hafta önce CVE-2026-39808 [KRİTİK] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2026-25089 [KRİTİK] CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce
İdeal Çözümler // Altyapı Güvenlik İstihbaratı

RADAR

Altyapının nabzı, tehditlerin ekranı.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS ve 6 platform daha için güvenlik açıkları, kritik yamalar ve sürüm gelişmeleri — tek ekranda, doğrulanmış ve işlem yapılabilir.

Aktif Duyuru
0
Kritik Seviye
0
Son 30 Gün
0
Okunma
0
Arama

Canlı Duyuru Akışı

FİLTREYİ SIFIRLA ↺
FortiGate / FortiOS 12 May 2026
Yüksek · 8.3

Out-of-bounds access in CAPWAP daemon

CVSSv3 Score: 8.3 An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device Revised on 2026-05-12 00:00:00

FG-IR-26-123 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Orta · 5.0

OTP Disclosure via Exported TokenContentProvider

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

FG-IR-26-130 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Orta · 6.5

OS command injection in CLI

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00

FG-IR-26-133 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Kritik · 9.1

Incorrect global authorization

CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00

FG-IR-26-136 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Kritik · 9.1

Improper access control on API endpoints

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-128 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Düşük · 2.1

Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

FG-IR-26-129 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Orta · 5.2

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

FG-IR-26-137 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Orta · 6.1

Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

FG-IR-26-131 Güvenlik Açığı 0
FortiGate / FortiOS 12 May 2026
Orta · 4.0

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-138 Güvenlik Açığı 0