Achieving 100% Observability with BIND and Zabbix · 38 minutes ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago Achieving 100% Observability with BIND and Zabbix · 38 minutes ago CVE-2025-68686 [CRITICAL] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 days ago CVE-2024-1086 USN-7001-1: Linux kernel critical security update · 1 week ago Proxmox Virtual Environment - Security Advisories · 1 week ago CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 week ago CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 week ago CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 week ago CVE-2026-45695 [CRITICAL] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 week ago Plesk Obsidian 18.0.x security micro-updates released · 1 week ago CVE-2026-39808 [CRITICAL] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

FortiGate / FortiOS Feed

RESET FILTERS ↺
FortiGate / FortiOS 27 Jul 2026
Critical

CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

CVE-2025-68686 CISA-KEV Vulnerability 24
FortiGate / FortiOS 16 Jul 2026
Critical

CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-25089 CISA-KEV Vulnerability 2
FortiGate / FortiOS 09 Jun 2026
Critical · 9.1

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

FG-IR-26-141 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Critical · 9.1

Improper access control on API endpoints

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00

FG-IR-26-128 Vulnerability 2
FortiGate / FortiOS 12 May 2026
Critical · 9.1

Incorrect global authorization

CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00

FG-IR-26-136 Vulnerability 2
FortiGate / FortiOS 27 Jan 2026
Critical

CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CVE-2026-24858 CISA-KEV Vulnerability 2
FortiGate / FortiOS 16 Dec 2025
Critical

CVE-2025-59718 — Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

CVE-2025-59718 CISA-KEV Vulnerability 2
FortiGate / FortiOS 18 Nov 2025
Critical

CVE-2025-58034 — Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CVE-2025-58034 CISA-KEV Vulnerability 1
FortiGate / FortiOS 14 Nov 2025
Critical

CVE-2025-64446 — Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CVE-2025-64446 CISA-KEV Vulnerability 1

From the agenda

See all →