ZeroHour

Search: “FortiFone”

18 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Fortinet security advisory (AV26-023) - Update 1

CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.

The Canadian Centre for Cyber Security updated advisory AV26-023, which relays January 2026 Fortinet advisories covering FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. On September 9, 2026, CISA added CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its Known Exploited Vulnerabilities catalog. Related Fortinet flaws include unauthenticated local configuration access (CVE-2025-47855) and unauthenticated remote command injection (CVE-2025-64155). Administrators should review the advisories and apply available updates.

Canadian Centre for Cyber Securityupdated · 6d agofirst · 6d agoExploit / PoC in the wild 3 sourcesCVE-2025-25249CVE-2025-47855CVE-2025-64155

UI DoS attack

FortiOS web interface is vulnerable to unauthenticated slow HTTP denial-of-service attacks via crafted requests (CVSS 5.0).

Fortinet advisory FG-IR-26-162 details an unbounded resource allocation flaw (CWE-770) in FortiOS, scored CVSSv3 5.0. An unauthenticated attacker can launch a slow HTTP denial-of-service attack against the FortiOS web interface using crafted HTTP requests. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.

Fortinet PSIRT · Aug 12, 2026Advisory

Server-Side Request Forgery (SSRF)

Fortinet discloses a low-severity SSRF in the FortiSIEM GUI allowing authenticated attackers to send requests from targeted devices.

Fortinet PSIRT advisory FG-IR-26-159, revised 2026-08-12, describes a server-side request forgery (CWE-918) in the FortiSIEM GUI, scored CVSSv3 3.4. An authenticated attacker can send HTTP requests originating from the targeted device via specially crafted requests, potentially enabling internal network probing. No CVE identifier or exploitation status is included in the advisory text.

Fortinet PSIRT · Aug 12, 2026Advisory

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Fortinet disclosed CVE-2026-26084 (CVSS 8.9), an unauthenticated information-disclosure flaw in the FortiSandbox web UI, urging upgrades.

Fortinet patched CVE-2026-26084, a CWE-284 improper access control flaw in the shared web UI of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS that lets unauthenticated attackers read sensitive data via crafted HTTP requests. Affected releases include FortiSandbox 5.0.0-5.0.5 and 4.4.0-4.4.8, Cloud 5.0.4-5.0.5, and PaaS 5.0.4-5.0.5; fixes arrive in 5.0.6+ and 4.4.9+, while FortiSandbox 5.2 and Cloud 4.4 are unaffected. The issue was found internally by Fortinet's Product Security team, and the company reports no evidence of exploitation in the wild. Disclosure carries only confidentiality impact, but exposed sandbox configurations and logs could aid follow-on attacks.

Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

Attackers actively exploit CVE-2025-25249 in FortiGate firewalls to deploy PivotC2, a Node.js RAT that decrypts VPN and admin credentials.

SOCRadar assesses with high confidence that threat actors are actively exploiting CVE-2025-25249, a CVSS 9.8 heap buffer overflow in the cw_acd daemon (CAPWAP, UDP 5246) affecting FortiOS 6.4-7.6.3 and FortiSwitchManager 7.0.x/7.2.x. Attackers deploy fortirun.bin and PivotC2, a Node.js post-exploitation framework that harvests configurations and decrypts SSL-VPN, wireless, and admin credentials using AES-256-CBC and AES-128-GCM. Over 30,000 FortiGate IPs were scanned and 178 devices compromised, including two confirmed full intrusions of US organizations with Exchange mailbox exfiltration to Wasabi storage. STRU attributes the campaign to a Russian-speaking, financially motivated cybercrime operator.

Cyber Security News · 7d agoExploit / PoC in the wildCVE-2025-252491

Arbitrary process termination from exposed minifilter communication port

Fortinet FortiClient Windows fortimon3 driver flaw (CVSS 4.7) lets authenticated attackers terminate arbitrary processes via exposed minifilter communication port.

Fortinet advisory FG-IR-26-165 discloses an unverified ownership vulnerability (CWE-283, CVSSv3 4.7) in the FortiClient Windows fortimon3 minifilter driver. An authenticated attacker can terminate arbitrary processes through an exposed minifilter communication port. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory1

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet discloses high-severity certificate validation flaw CVE-2026-84393 in FortiOS and FortiProxy Agentless ZTNA portals enabling unauthenticated man-in-the-middle attacks.

Fortinet disclosed CVE-2026-84393 (CVSSv3 7.3, CWE-295) on September 8, 2026 under advisory FG-IR-26-174: improper certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. An unauthenticated attacker on the network path could present a forged or mismatched certificate and intercept or tamper with traffic between the portal and backend destinations, with impact classified as information disclosure. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; the 8.0, 7.4 and 7.2 branches of both products are unaffected. Fortinet urges upgrading to 7.6.7 or later and reports no evidence of exploitation in the wild.

Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

Fortinet fixed CVE-2026-26084, an unauthenticated access-control flaw in FortiSandbox GUI rated 8.9 CVSS, with no known exploitation yet.

Fortinet disclosed CVE-2026-26084 (advisory FG-IR-26-166), a CWE-284 improper access control flaw in the GUI of FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS, rated 8.9 CVSS v3.1. An unauthenticated remote attacker can send specially crafted HTTP requests to control NAT rules and expose sensitive information. Affected versions include FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 (plus Cloud/PaaS 5.0.4-5.0.5), fixed in 4.4.9 and 5.0.6. Fortinet researcher Adham El Karn found the flaw internally and the September 8 advisory reports no known exploitation.

GBHackers · 7d agoVulnerabilityCVE-2026-26084

Fortinet Confirms Critical Zero Day

Fortinet has confirmed a critical zero-day vulnerability; the available headline provides no product, CVE, or exploitation details.

Infosecurity Magazine's headline states that Fortinet has confirmed a critical zero-day vulnerability. The available source text contains no additional details on affected products, CVE identifiers, exploitation status, or available fixes. Defenders should treat specifics as unconfirmed pending a vendor advisory.

Infosecurity Magazine · Aug 16, 2026Exploit / PoC in the wild

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

Fortinet fixed an improper access control flaw (CVSS 8.9) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS letting unauthenticated attackers access sensitive information.

Fortinet advisory FG-IR-26-166 discloses an improper access control vulnerability (CWE-284) in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI, rated CVSSv3 8.9. The advisory title indicates unauthenticated control of NAT rules leading to exposure of sensitive information. An unauthenticated attacker can access sensitive data via crafted HTTP requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Fortra security advisory (AV26-906)

Canada's Cyber Centre advises that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability.

The Canadian Centre for Cyber Security issued advisory AV26-906 noting that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability. The advisory was published September 10, 2026, referencing Fortra's own security advisory. No exploitation details or CVE id are provided; administrators are urged to review the links and apply the 7.10.2 update.

Canadian Centre for Cyber Security · 6d agoAdvisory

Fortinet security advisory (AV26-898)

Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.

Canadian Centre for Cyber Security · 7d agoAdvisory

Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT

SOCRadar says attackers exploit FortiGate CVE-2025-25249 to deploy the PivotC2 Node.js RAT, compromising 178 of 30,000 targeted devices and stealing credentials.

SOCRadar's Threat Research Unit reports active exploitation of CVE-2025-25249, a CVSS 9.8 heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, via crafted CAPWAP requests to UDP port 5246, compromising at least 178 of 30,000 targeted internet-exposed FortiGate devices since July 2026. The campaign deploys PivotC2, a Node.js RAT that provides interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning, and automated configuration harvesting that decrypts stored FortiGate credentials, including VPN pre-shared keys, SSL-VPN credentials, and LDAP secrets. Russian-language artifacts, AD enumeration, browser credential theft, RDP enablement, and exfiltration of Exchange .pst files to Wasabi S3 point to a Russian-speaking, financially motivated group; two US organizations confirmed full-network intrusions. Fixes include FortiOS 7.6.4/7.4.9/7.2.12/7.0.18+ and FortiSwitchManager 7.2.7/7.0.6+, plus blocking CAPWAP on internet-facing interfaces.

GBHackers · 7d agoMalware in the wildCVE-2025-252492

Fortinet Vulnerability Ransomware

Ransomware operators are exploiting a Fortinet vulnerability, per the Infosecurity Magazine headline; article details unavailable.

Infosecurity Magazine's headline indicates ransomware activity tied to a Fortinet vulnerability. The article body was not available, so the specific CVE, affected versions and victim details are unconfirmed.

Infosecurity Magazine · Aug 16, 2026Exploit / PoC in the wild

The 12 Best Managed Detection & Response (MDR) Services, Compared and Priced

Buyer's guide compares 12 MDR services, naming Huntress best value, CrowdStrike Falcon Complete for response authority and Expel for transparency.

The article compares 12 managed detection and response providers across response authority, tool bundling and pricing, highlighting Huntress for published SMB pricing and CrowdStrike Falcon Complete for unilateral containment. It stresses the consolidation landscape: Sophos completed its acquisition of Secureworks in February 2025 for approximately $859 million, and Arctic Wolf closed its purchase of BlackBerry's Cylance endpoint assets the same month. It also warns that only full-response contract tiers isolate hosts and kill processes, while lower tiers only triage or guide.

GBHackersupdated · 7d agofirst · 7d agoIndustry 3 sources1

Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider

Exposed attacker staging server reveals intrusion of Thai broadband provider 3BB via actively exploited FortiGate SSL-VPN flaw CVE-2024-21762.

Hunt.io found an open directory on server 92.63.180[.]133 holding 298 files detailing an intrusion into Triple T Broadband's 3BB brand, starting from a FortiGate 60F SSL-VPN at mail.3bb.co[.]th:10443. The actor weaponized CVE-2024-21762 (CVSS 9.8, KEV-listed since February 2024) using heap spraying and a ROP chain to gain a reverse shell. Post-exploitation included MeshCentral root-level persistence via www.ayuthayatech[.]com, Dirty COW/PwnKit privilege escalation, credential harvesting, SSH spraying against 55+ internal addresses, and log-deleting cleanup scripts; a stolen OpenVPN certificate and key from Triple T's PKI may still be valid.

Cyber Security Newsupdated · 1d agofirst · 1d agoExploit / PoC in the wild 3 sourcesCVE-2024-217622

The 12 Best Managed Firewall Services, Compared and Priced

GBHackers compares 12 managed firewall service providers, naming Fortinet best value and Secureworks best detection while flagging recent ownership changes.

The buyer's guide evaluates 12 managed firewall/MSSP providers across cost tiers, contract terms, and service models. Fortinet is rated best value, Secureworks best detection, NTT Data best global reach, and Cato Networks best for organizations wanting to stop owning firewalls. The article highlights that Secureworks was acquired by Sophos for roughly $859 million in February 2025, the Trustwave-Cybereason merger was terminated in March 2025, LevelBlue is the rebranded AT&T Cybersecurity business, and Comcast Business absorbed Masergy.

GBHackers · 8d agoIndustry 2 sources