Achieving 100% Observability with BIND and Zabbix · 1 hour ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago Achieving 100% Observability with BIND and Zabbix · 1 hour ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

FortiGate / FortiOS Feed

RESET FILTERS ↺
FortiGate / FortiOS 14 Jul 2026
Medium · 4.1

Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

FG-IR-26-154 Vulnerability 2
FortiGate / FortiOS 14 Jul 2026
Medium · 5.3

Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

FG-IR-26-149 Vulnerability 2
FortiGate / FortiOS 14 Jul 2026
Medium · 5.0

Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

FG-IR-26-151 Vulnerability 2
FortiGate / FortiOS 14 Jul 2026
Medium · 6.1

SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00

FG-IR-26-150 Vulnerability 3
FortiGate / FortiOS 14 Jul 2026
Medium · 5.9

Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00

FG-IR-26-148 Vulnerability 2
FortiGate / FortiOS 14 Jul 2026
Medium · 6.9

Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00

FG-IR-26-155 Vulnerability 4
FortiGate / FortiOS 09 Jun 2026
Medium · 6.2

Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00

FG-IR-26-140 Vulnerability 2
FortiGate / FortiOS 09 Jun 2026
Medium · 6.0

Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

FG-IR-26-143 Vulnerability 4
FortiGate / FortiOS 12 May 2026
Medium · 4.0

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-138 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Medium · 6.1

Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

FG-IR-26-131 Vulnerability 4
FortiGate / FortiOS 12 May 2026
Medium · 5.2

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

FG-IR-26-137 Vulnerability 2

From the agenda

See all →