Fortinet security advisory (AV26-898)
Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates
The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.
- Covers FortiOS 7.6, FortiProxy 7.6, FortiPAM extensions, FortiSandbox 4.4/5.0, FortiMonitorOnSight 7.2
- Advisory AV26-898 urges review of linked Fortinet PSIRT advisories and prompt patching
- No specific CVE identifiers or exploitation details provided in the bulletin
Full article104 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-898
Date: September 9, 2026
As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products:
- FortiOS 7.6
- Versions 7.6.1 to 7.6.6
- FortiProxy 7.6
- Versions 7.6.2 to 7.6.6
- FortiPAM Chrome Extension 8.0
- All versions
- FortiPAM Chrome Extension 7.4
- All versions
- FortiSandbox 5.0
- Versions 5.0.0 to 5.0.5
- FortiSandbox 4.4
- Versions 4.4.0 to 4.4.8
- FortiSandbox Cloud 5.0
- Versions 5.0.4 to 5.0.5
- FortiSandbox PaaS 5.0
- Versions 5.0.4 to 5.0.5
- FortiMonitorOnSight 7.2
- Versions 7.2.4 to 7.2.7
- FortiMonitorOnSight 7.2
- Versions 7.2.0 to 7.2.2
The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-898