CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

Live Advisory Feed

RESET FILTERS ↺
FortiGate / FortiOS 08 Sep 2026
Critical · 9.1

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

FG-IR-26-168 Vulnerability 34
FortiGate / FortiOS 08 Sep 2026
Critical · 9.6

JWT used for authentication in web GUI signed with static key

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

FG-IR-26-170 Vulnerability 46
FortiGate / FortiOS 08 Sep 2026
Low · 2.5

Null Pointer Dereference in Log Report

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00

FG-IR-26-173 Vulnerability 54
FortiGate / FortiOS 08 Sep 2026
Low · 2.8

Open Redirect on FortiSIEM

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

FG-IR-26-169 Vulnerability 30
FortiGate / FortiOS 08 Sep 2026
High · 8.9

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

CVSSv3 Score: 8.9 An improper access control vulnerability in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

FG-IR-26-166 Vulnerability 32
FortiGate / FortiOS 08 Sep 2026
Medium · 5.9

Uncontrolled Resource Consumption in SNMP

CVSSv3 Score: 5.9 A Use of Uninitialized Variable vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

FG-IR-26-172 Vulnerability 33
FortiGate / FortiOS 08 Sep 2026
Medium · 4.7

Workflow session email approval process bypass

CVSSv3 Score: 4.7 An improper access control vulnerability in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00

FG-IR-26-171 Vulnerability 42
FortiGate / FortiOS 08 Sep 2026
High · 7.3

ZTNA Portal Improper Certificate Validation

CVSSv3 Score: 7.3 An improper certificate validation vulnerability in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00

FG-IR-26-174 Vulnerability 38
Windows Server 02 Sep 2026
High · 8.6

CVE-2026-84452 — Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML.

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/buil

CVE-2026-84452 Vulnerability 30
Windows Server 01 Sep 2026
Critical · 9.0

CVE-2026-75604 — Next.js is a React framework for building full-stack web applications.

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can

CVE-2026-75604 Vulnerability 30
Proxmox VE 01 Sep 2026
Critical · 9.3

CVE-2023-54391 — Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-contro

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification

CVE-2023-54391 Vulnerability 43
Windows Server 01 Sep 2026
High · 8.8

CVE-2026-19591 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell

OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separat

CVE-2026-19591 Vulnerability 24

From the agenda

See all →