CVE-2025-68686 [KRİTİK] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 gün önce CVE-2024-1086 USN-7001-1: Linux çekirdeği kritik güvenlik güncellemesi · 1 hafta önce Proxmox Virtual Environment - Security Advisories · 1 hafta önce CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 hafta önce CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 hafta önce CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 hafta önce CVE-2026-45695 [KRİTİK] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 hafta önce Plesk Obsidian 18.0.x güvenlik mikro-güncellemeleri yayınlandı · 1 hafta önce CVE-2026-39808 [KRİTİK] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2026-25089 [KRİTİK] CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2025-68686 [KRİTİK] CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to... · 2 gün önce CVE-2024-1086 USN-7001-1: Linux çekirdeği kritik güvenlik güncellemesi · 1 hafta önce Proxmox Virtual Environment - Security Advisories · 1 hafta önce CVE-2026-51083 CVE-2026-51083 — Incorrect access control in Proxmox Virtual Environme... · 1 hafta önce CVE-2026-51082 CVE-2026-51082 — A race condition between the vncproxy and vncwebsocke... · 1 hafta önce CVE-2026-51081 CVE-2026-51081 — A cross-site scripting (XSS) vulnerability in Proxmox... · 1 hafta önce CVE-2026-45695 [KRİTİK] CVE-2026-45695 — Kopia is a cross-platform backup tool for Windows, ma... · 1 hafta önce Plesk Obsidian 18.0.x güvenlik mikro-güncellemeleri yayınlandı · 1 hafta önce CVE-2026-39808 [KRİTİK] CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce CVE-2026-25089 [KRİTİK] CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerabil... · 1 hafta önce
İdeal Çözümler // Altyapı Güvenlik İstihbaratı

RADAR

Altyapının nabzı, tehditlerin ekranı.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS ve 6 platform daha için güvenlik açıkları, kritik yamalar ve sürüm gelişmeleri — tek ekranda, doğrulanmış ve işlem yapılabilir.

Aktif Duyuru
0
Kritik Seviye
0
Son 30 Gün
0
Okunma
0
Arama

FortiGate / FortiOS Akışı

FİLTREYİ SIFIRLA ↺
FortiGate / FortiOS 27 Tem 2026
Kritik

CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

CVE-2025-68686 CISA-KEV Güvenlik Açığı 8
FortiGate / FortiOS 16 Tem 2026
Kritik

CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-25089 CISA-KEV Güvenlik Açığı 2
FortiGate / FortiOS 14 Tem 2026
Orta · 4.1

Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

FG-IR-26-154 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Orta · 5.3

Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

FG-IR-26-149 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Düşük · 3.4

Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00

FG-IR-26-152 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Düşük · 3.1

Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00

FG-IR-26-153 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Yüksek · 7.0

Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00

FG-IR-26-146 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Orta · 5.0

Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00

FG-IR-26-151 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Orta · 6.1

SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00

FG-IR-26-150 Güvenlik Açığı 1
FortiGate / FortiOS 14 Tem 2026
Orta · 5.9

Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00

FG-IR-26-148 Güvenlik Açığı 1