CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

FortiGate / FortiOS Feed

RESET FILTERS ↺
FortiGate / FortiOS 08 Sep 2026
Critical · 9.1

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00

FG-IR-26-168 Vulnerability 34
FortiGate / FortiOS 08 Sep 2026
Critical · 9.6

JWT used for authentication in web GUI signed with static key

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

FG-IR-26-170 Vulnerability 46
FortiGate / FortiOS 27 Jul 2026
Critical

CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

CVE-2025-68686 CISA-KEV Vulnerability 65
FortiGate / FortiOS 16 Jul 2026
Critical

CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-25089 CISA-KEV Vulnerability 39
FortiGate / FortiOS 09 Jun 2026
Critical · 9.1

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

FG-IR-26-141 Vulnerability 35
FortiGate / FortiOS 12 May 2026
Critical · 9.1

Improper access control on API endpoints

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-128 Vulnerability 32
FortiGate / FortiOS 12 May 2026
Critical · 9.1

Incorrect global authorization

CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00

FG-IR-26-136 Vulnerability 39
FortiGate / FortiOS 27 Jan 2026
Critical

CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CVE-2026-24858 CISA-KEV Vulnerability 37

From the agenda

See all →