Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
Fortinet Issues Patches for 40 Flaws Affecting FortiWeb, FortiOS, FortiNAC, and FortiProxyThe Hacker News·Feb 23, 03:50 UTC · Feb 23, 2023Vulnerability in the wildCVE-2022-39952CVE-2021-4275660
Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)Help Net Security·Jul 19, 15:00 UTC · Jul 19, 2025Vulnerability in the wildCVE-2025-2525760
Fortinet addresses 4 vulnerabilities in FortiWeb web application firewallsSecurity Affairs·Feb 5, 08:33 UTC · Feb 5, 2021VulnerabilityCVE-2020-29015CVE-2020-29016CVE-2020-29019+1 CVEs47
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025The Hacker News·Jul 12, 06:33 UTC · Jul 12, 2025VulnerabilityCVE-2025-25257CVE-2025-20286CVE-2025-20281+1 CVEs60
Fortinet FortiWeb OS Command Injection allows takeover servers remotelySecurity Affairs·Aug 17, 15:31 UTC · Aug 17, 2021VulnerabilityCVE-2020-2901535
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
Fortinet fixes critical vulnerabilities in FortiNAC and FortiWebSecurity Affairs·Feb 17, 15:09 UTC · Feb 17, 2023VulnerabilityCVE-2022-39952CVE-2021-4275660
Unpatched Fortinet FortiWeb vulnerability allows remote OS command injectionHelp Net Security·Aug 17, 00:00 UTC · Aug 17, 2021VulnerabilityCVE-2021-2212335
Flaws in Fortinet FortiWeb WAF could allow corporate networks to hackSecurity Affairs·Jan 7, 14:23 UTC · Jan 7, 2021VulnerabilityCVE-2020-29015CVE-2020-29016CVE-2020-29018+1 CVEs35
Stealth-patched FortiWeb vulnerability under active exploitation (CVE-2025-58034)Help Net Security·Nov 19, 00:00 UTC · Nov 19, 2025Vulnerability in the wildCVE-2025-58034CVE-2025-6444660
Hackers are exploiting critical Fortinet flaws days after patch releaseSecurity Affairs·Dec 16, 15:40 UTC · Dec 16, 2025VulnerabilityCVE-2025-59718CVE-2025-5971960
Unpatched Remote Hacking Flaw Disclosed in Fortinet's FortiWeb WAFThe Hacker News·Aug 19, 06:50 UTC · Aug 19, 2021Vulnerability in the wildCVE-2021-22123CVE-2020-29015CVE-2018-13379+2 CVEs60
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation DetectedThe Hacker News·Jan 29, 06:05 UTC · Jan 29, 2026Vulnerability in the wildCVE-2026-2485860
CISA gives federal agencies one week to patch exploited Fortinet bugThe Record·Nov 17, 13:33 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-64446160
Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root CodeThe Hacker News·Jul 17, 05:37 UTC · Jul 17, 2025VulnerabilityCVE-2025-20337CVE-2025-20281CVE-2025-20286+2 CVEs60
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution FlawsThe Hacker News·Dec 10, 09:13 UTC · Dec 10, 2025VulnerabilityCVE-2025-59718CVE-2025-59719CVE-2025-10573+6 CVEs60
Approov Alliance and Integration Program offers security solutions to protect APIsHelp Net Security·Sep 16, 08:03 UTC · Sep 16, 2024Vulnerability55
Week in review: Realtek chips vulnerabilities, NAS devices under attack, security teams burnoutHelp Net Security·Aug 22, 00:00 UTC · Aug 22, 2021VulnerabilityCVE-2021-2837260
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code ExecutionThe Hacker News·Feb 10, 13:59 UTC · Feb 10, 2026Vulnerability in the wildCVE-2026-21643CVE-2026-2485860
Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026Security Affairs·Jan 28, 15:58 UTC · Jan 28, 2026Vulnerability in the wildCVE-2026-24858CVE-2025-59718CVE-2025-5971960
Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall ConfigurationsThe Hacker News·Jan 22, 05:55 UTC · Jan 22, 2026VulnerabilityCVE-2025-59718CVE-2025-5971935
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN VulnerabilityThe Hacker News·Dec 23, 04:10 UTC · Dec 23, 2025Vulnerability in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication BypassThe Hacker News·Dec 17, 03:57 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-59718CVE-2025-5971960
Attackers are exploiting auth bypass vulnerability on FortiGate firewalls (CVE-2025-59718)Help Net Security·Dec 17, 00:00 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-59718CVE-2025-5971960
Fortinet enhances FortiAnalyzer to deliver accelerated threat hunting and incident responseHelp Net Security·Feb 19, 00:00 UTC · Feb 19, 2025Vulnerability55
Fortinet releases patches for publicly undisclosed critical FortiManager vulnerabilityHelp Net Security·Oct 24, 15:15 UTC · Oct 24, 2024VulnerabilityCVE-2024-2311360
CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active ZeroThe Hacker News·Oct 23, 05:48 UTC · Oct 23, 2024Vulnerability in the wildCVE-2024-9537CVE-2024-2311360
CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security PatchesThe Hacker News·Oct 12, 04:56 UTC · Oct 12, 2024Vulnerability in the wildCVE-2024-23113CVE-2024-9463CVE-2024-9464+4 CVEs60
Fortinet fixed a critical vulnerability in its Data Analytics productSecurity Affairs·Apr 13, 10:30 UTC · Apr 13, 2023VulnerabilityCVE-2022-41331CVE-2022-43955CVE-2022-27487+1 CVEs60