CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 1 week ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 1 week ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

Live Advisory Feed

RESET FILTERS ↺
FortiGate / FortiOS 12 May 2026
Medium · 4.0

Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-138 Vulnerability 26
FortiGate / FortiOS 12 May 2026
Medium · 6.1

Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

FG-IR-26-131 Vulnerability 22
FortiGate / FortiOS 12 May 2026
Medium · 5.2

DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

FG-IR-26-137 Vulnerability 31
FortiGate / FortiOS 12 May 2026
Medium · 6.5

OS command injection in CLI

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00

FG-IR-26-133 Vulnerability 27
FortiGate / FortiOS 12 May 2026
Medium · 5.0

OTP Disclosure via Exported TokenContentProvider

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

FG-IR-26-130 Vulnerability 27
FortiGate / FortiOS 12 May 2026
Medium · 6.3

SQL command injection in administrative portal

CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests. Revised on 2026-05-12 00:00:00

FG-IR-26-132 Vulnerability 36
FortiGate / FortiOS 12 May 2026
Medium · 5.1

User controlled SQL commands

CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests. Revised on 2026-05-12 00:00:00

FG-IR-26-134 Vulnerability 33
cPanel & WHM 08 May 2026
Medium · 5.3

CVE-2026-29203 — A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on

A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory.

CVE-2026-29203 Vulnerability 14
MikroTik RouterOS 05 May 2026
Medium · 6.5

CVE-2025-42611 — RouterOS provides various services that rely on correct verification of client and server certificates to secure confide

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes confusion of scope, allowing any certificate authority present in the system-wid

CVE-2025-42611 Vulnerability 14
FortiGate / FortiOS 15 Apr 2026
Medium · 6.7

Out-Of-Bounds Write in administrative interface

CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. Revised on 2026-04-15 00:00:00

FG-IR-26-127 Vulnerability 27
FortiGate / FortiOS 14 Apr 2026
Medium · 6.7

2FA request can be replayed without a valid token after one successful request

CVSSv3 Score: 6.7 An Improper authentication vulnerability [CWE-287] in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration. Revised on 2026-04-14 00:00:00

FG-IR-26-101 Vulnerability 27
FortiGate / FortiOS 14 Apr 2026
Medium · 6.2

Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

FG-IR-26-115 Vulnerability 28

From the agenda

See all →