Achieving 100% Observability with BIND and Zabbix · 37 minutes ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago Achieving 100% Observability with BIND and Zabbix · 37 minutes ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

FortiGate / FortiOS Feed

RESET FILTERS ↺
FortiGate / FortiOS 14 Jul 2026
Medium · 6.9

Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00

FG-IR-26-155 Vulnerability 3
FortiGate / FortiOS 14 Jul 2026
High · 7.7

Unauthenticated VNC access exposed on all interfaces

CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00

FG-IR-26-145 Vulnerability 2
FortiGate / FortiOS 09 Jun 2026
Medium · 6.2

Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00

FG-IR-26-140 Vulnerability 2
FortiGate / FortiOS 09 Jun 2026
Medium · 6.0

Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

FG-IR-26-143 Vulnerability 2
FortiGate / FortiOS 09 Jun 2026
Critical · 9.1

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

FG-IR-26-141 Vulnerability 2
FortiGate / FortiOS 03 Jun 2026
High · 7.9

Linux Kernel vulnerability Dirty Frag

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a privat

CVE-2026-43284 FG-IR-26-144 Vulnerability 2
FortiGate / FortiOS 13 May 2026
High · 7.8

Linux Kernel Vulnerability copy.fail - CVE-2026-31431

CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. Revised on 2026-05-13 00:00:00

CVE-2026-31431 FG-IR-26-139 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Medium · 4.0

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-138 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Medium · 6.1

Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

FG-IR-26-131 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Medium · 5.2

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

FG-IR-26-137 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Low · 2.1

Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

FG-IR-26-129 Vulnerability 2

From the agenda

See all →