ZeroHour

Search: “FortiPAM”

3 stories in the last 30d

Improper Authentication of FortiPAM Server

Fortinet discloses CVSS 9.1 improper authentication in FortiPAM's Chrome extension allowing unauthenticated attackers to proxy victims' browser traffic.

Fortinet advisory FG-IR-26-168 describes an improper authentication vulnerability (CWE-287) rated 9.1 in the Fortinet Privileged Access Agent Chrome Extension. A remote unauthenticated attacker could proxy a user's browser traffic through attacker-controlled servers if the user visits a malicious website. The advisory was revised on September 8, 2026.

Fortinet PSIRT · 9d agoAdvisory

Fortinet security advisory (AV26-898)

Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.

Canadian Centre for Cyber Security · 7d agoAdvisory1

Null Pointer Dereference in Log Report

Fortinet patched a low-severity null pointer dereference (CVSS 2.5) in FortiOS, FortiProxy, and FortiPAM that lets authenticated attackers crash the httpsd daemon.

Fortinet advisory FG-IR-26-173 describes a NULL pointer dereference vulnerability (CWE-476) in FortiOS, FortiProxy, and FortiPAM, scored CVSSv3 2.5. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests, causing a denial of service. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 9d agoAdvisory