ZeroHour

Search: “FortiSOAR”

22 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Broken Access control on Websocket streams

Fortinet FortiSOAR access control flaw (CVSS 4.9) lets zero-permission authenticated attackers subscribe to and inject broadcast messages into websocket streams.

Fortinet advisory FG-IR-26-164 discloses an improper access control vulnerability (CWE-284, CVSSv3 4.9) in FortiSOAR. An authenticated attacker with zero permissions can subscribe to websocket streams and topics and inject broadcast messages via crafted websocket requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Fortinet patched 10 vulnerabilities including two critical authentication flaws, CVE-2026-84390 (CVSS 9.6) and CVE-2026-84388 (CVSS 9.1), in FortiMonitorOnSight and the FortiPAM Chrome extension.

Fortinet's September patch release fixes CVE-2026-84390, a sensitive-information issue in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs. CVE-2026-84388 is an improper authentication flaw in the Fortinet Privileged Access Agent Chrome extension that can allow attackers to proxy a user's browser traffic via a malicious website, requiring upgrades to both FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity information disclosure in FortiSandbox (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393) were also fixed, alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others. Fortinet did not indicate any of the flaws are being exploited in the wild.

CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) allowing unauthorized code execution by sending specially crafted packets. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, with a September 12 remediation deadline for federal agencies under BOD 26-04 and mandatory forensic triage of affected environments. Internet-facing Fortinet firewalls and SASE platforms are a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown.

Cyber Security Newsupdated · 6d agofirst · 6d agoExploit / PoC in the wild 6 sourcesCVE-2025-252492

Fortra security advisory (AV26-906)

Canada's Cyber Centre advises that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability.

The Canadian Centre for Cyber Security issued advisory AV26-906 noting that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability. The advisory was published September 10, 2026, referencing Fortra's own security advisory. No exploitation details or CVE id are provided; administrators are urged to review the links and apply the 7.10.2 update.

Canadian Centre for Cyber Security · 6d agoAdvisory

FGFM Authentication Weakening via CLI Configuration

FortiManager FGFM flaw (CVSS 7.3) lets an attacker with a valid certificate impersonate any managed FortiGate under a specific CLI option.

Fortinet advisory FG-IR-26-160 describes an authentication bypass via alternate path (CWE-288) in FortiManager and FortiManager Cloud, scored CVSSv3 7.3. A remote unauthenticated attacker holding a valid certificate can impersonate any FortiGate managed by the affected FortiManager when a specific CLI option is set. The impersonation is performed with crafted FGFM protocol requests. The advisory was revised on 2026-08-12 and does not report active exploitation.

Fortinet PSIRT · Aug 12, 2026Advisory

Arbitrary process termination from exposed minifilter communication port

Fortinet FortiClient Windows fortimon3 driver flaw (CVSS 4.7) lets authenticated attackers terminate arbitrary processes via exposed minifilter communication port.

Fortinet advisory FG-IR-26-165 discloses an unverified ownership vulnerability (CWE-283, CVSSv3 4.7) in the FortiClient Windows fortimon3 minifilter driver. An authenticated attacker can terminate arbitrary processes through an exposed minifilter communication port. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory1

Workflow session email approval process bypass

Fortinet disclosed an improper access control flaw (CVSS 4.7) in FortiManager allowing administrators to bypass workflow session email approval via crafted HTTP requests.

Fortinet advisory FG-IR-26-171 covers an improper access control vulnerability (CWE-284) in FortiManager, rated CVSSv3 4.7. An administrator can bypass the approval process for workflow sessions via crafted HTTP or HTTPS requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Server-Side Request Forgery (SSRF)

Fortinet discloses a low-severity SSRF in the FortiSIEM GUI allowing authenticated attackers to send requests from targeted devices.

Fortinet PSIRT advisory FG-IR-26-159, revised 2026-08-12, describes a server-side request forgery (CWE-918) in the FortiSIEM GUI, scored CVSSv3 3.4. An authenticated attacker can send HTTP requests originating from the targeted device via specially crafted requests, potentially enabling internal network probing. No CVE identifier or exploitation status is included in the advisory text.

Fortinet PSIRT · Aug 12, 2026Advisory

Fortinet Vulnerability Ransomware

Ransomware operators are exploiting a Fortinet vulnerability, per the Infosecurity Magazine headline; article details unavailable.

Infosecurity Magazine's headline indicates ransomware activity tied to a Fortinet vulnerability. The article body was not available, so the specific CVE, affected versions and victim details are unconfirmed.

Infosecurity Magazine · Aug 16, 2026Exploit / PoC in the wild

Fortinet security advisory (AV26-023) - Update 1

CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.

The Canadian Centre for Cyber Security updated advisory AV26-023, which relays January 2026 Fortinet advisories covering FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. On September 9, 2026, CISA added CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its Known Exploited Vulnerabilities catalog. Related Fortinet flaws include unauthenticated local configuration access (CVE-2025-47855) and unauthenticated remote command injection (CVE-2025-64155). Administrators should review the advisories and apply available updates.

Heap overflow in kernel driver due to missing size validation

Fortinet fixes a CVSS 7.3 heap overflow in the FortiClient Windows kernel driver enabling code execution via crafted DNS responses.

Fortinet PSIRT advisory FG-IR-26-156, revised 2026-08-12, describes a heap-based buffer overflow (CWE-120, buffer copy without checking input size) in the FortiClient Windows kernel driver, scored CVSSv3 7.3. An unauthenticated attacker positioned to alter or craft DNS responses for a targeted host could execute arbitrary code via malicious packets. No CVE identifier or exploitation status is provided in the advisory text, so administrators should check the full bulletin for affected versions and fixed releases.

Fortinet PSIRT · Aug 12, 2026Advisory

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

Fortra researchers track an active phishing campaign targeting Spanish speakers that abuses mshta.exe to run HTA payloads for reconnaissance and credential theft.

Fortra's FIRE team says a phishing campaign active since June 2026 targets Spanish-speaking users with invoice ('Facturación') and judicial ('Aviso Judicial') lures, many sent via libero.it/italiaonline.it infrastructure with SCL:-1 markings to bypass anti-spam. Clicking embedded links delivers an HTA launcher executed via mshta.exe, which hides its window off-screen, builds dynamic C2 URLs, and performs reconnaissance using WMI, PowerShell, and environment-variable inspection. A second-stage JavaScript dropper uses HTML smuggling to reconstruct a Base64-encoded ZIP in the browser, delivering a 7-Zip self-extracting executable disguised as a Firefox installer; staged design allows later delivery of credential stealers or ransomware. Defenders are urged to block archivogratuito[.]online and shortener domains goo[.]su, abrir[.]link, and abre[.]ai, and to restrict mshta.exe execution via AppLocker or ASR rules.

GBHackers · 4d agoPhishing & fraud in the wild1

UI DoS attack

FortiOS web interface is vulnerable to unauthenticated slow HTTP denial-of-service attacks via crafted requests (CVSS 5.0).

Fortinet advisory FG-IR-26-162 details an unbounded resource allocation flaw (CWE-770) in FortiOS, scored CVSSv3 5.0. An unauthenticated attacker can launch a slow HTTP denial-of-service attack against the FortiOS web interface using crafted HTTP requests. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.

Fortinet PSIRT · Aug 12, 2026Advisory

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

CISA, FBI, and South Korean agencies warn Gunra ransomware, with 51 victims since April 2025, exploits Fortinet flaws for double-extortion attacks on critical infrastructure.

CISA, the FBI, and South Korean agencies warned of Gunra ransomware attacks targeting healthcare, financial services, government, and professional services worldwide. The Conti-derived operation exploits internet-facing Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 for initial access, then deploys double extortion with Salsa20/ChaCha20 encryption and publishes non-payers on a leak site within five to seven days. Ransomware.Live lists 51 victims since April 2025, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group uses Impacket tools for SMB lateral movement and NTDS credential dumping, tampers with VDI authentication to accept a designated OTP value to bypass MFA, and launched a RaaS affiliate program in January 2026 under the new alias Golden Community.

The Hacker News · Aug 12, 2026Ransomware in the wildCVE-2024-55591CVE-2025-24472

Uncontrolled Resource Consumption in SNMP

Uninitialized variable flaw (CVSS 5.9) in FortiAnalyzer's SNMP daemon lets remote authenticated attackers cause denial of service via SNMP GETBULK requests.

Fortinet advisory FG-IR-26-172 describes a use of uninitialized variable vulnerability (CWE-457) in the FortiAnalyzer SNMP daemon, scored CVSSv3 5.9. A remote authenticated attacker with user-level permissions can cause a denial of service via SNMP GETBULK requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet discloses high-severity certificate validation flaw CVE-2026-84393 in FortiOS and FortiProxy Agentless ZTNA portals enabling unauthenticated man-in-the-middle attacks.

Fortinet disclosed CVE-2026-84393 (CVSSv3 7.3, CWE-295) on September 8, 2026 under advisory FG-IR-26-174: improper certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. An unauthenticated attacker on the network path could present a forged or mismatched certificate and intercept or tamper with traffic between the portal and backend destinations, with impact classified as information disclosure. Affected versions are FortiOS 7.6.1 through 7.6.6 and FortiProxy 7.6.2 through 7.6.6; the 8.0, 7.4 and 7.2 branches of both products are unaffected. Fortinet urges upgrading to 7.6.7 or later and reports no evidence of exploitation in the wild.

Fortinet security advisory (AV26-898)

Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.

Canadian Centre for Cyber Security · 7d agoAdvisory1

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

US and Korean agencies warn Gunra ransomware actors exploit Fortinet flaws and stealthily exfiltrate large data volumes, targeting critical infrastructure.

US and Korean authorities warned that Gunra ransomware actors exploit Fortinet vulnerabilities to gain access and use stealthy techniques to exfiltrate vast volumes of data, including from Microsoft services. The group is targeting critical infrastructure organizations. Defenders should prioritize Fortinet patching and watch for large, quiet data egress.

Infosecurity Magazine · Aug 12, 2026Ransomware in the wild

Open Redirect on FortiSIEM

Fortinet disclosed an open redirect flaw (CVSS 2.8) in FortiSIEM allowing authenticated attackers to redirect users to arbitrary websites via crafted HTTP requests.

Fortinet advisory FG-IR-26-169 covers an open redirect vulnerability (CWE-601) in FortiSIEM, rated CVSSv3 2.8. An authenticated attacker can cause a redirection to any website via specially crafted HTTP requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Hackers Exploit Critical FortiGate Flaw to Deploy AI-Assisted PivotC2 RAT

SOCRadar says attackers exploit FortiGate CVE-2025-25249 to deploy the PivotC2 Node.js RAT, compromising 178 of 30,000 targeted devices and stealing credentials.

SOCRadar's Threat Research Unit reports active exploitation of CVE-2025-25249, a CVSS 9.8 heap-based buffer overflow in the cw_acd daemon of FortiOS and FortiSwitchManager, via crafted CAPWAP requests to UDP port 5246, compromising at least 178 of 30,000 targeted internet-exposed FortiGate devices since July 2026. The campaign deploys PivotC2, a Node.js RAT that provides interactive shells, SOCKS5/HTTP proxying, port forwarding, network scanning, and automated configuration harvesting that decrypts stored FortiGate credentials, including VPN pre-shared keys, SSL-VPN credentials, and LDAP secrets. Russian-language artifacts, AD enumeration, browser credential theft, RDP enablement, and exfiltration of Exchange .pst files to Wasabi S3 point to a Russian-speaking, financially motivated group; two US organizations confirmed full-network intrusions. Fixes include FortiOS 7.6.4/7.4.9/7.2.12/7.0.18+ and FortiSwitchManager 7.2.7/7.0.6+, plus blocking CAPWAP on internet-facing interfaces.

GBHackers · 7d agoMalware in the wildCVE-2025-252492

Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider

Exposed attacker staging server reveals intrusion of Thai broadband provider 3BB via actively exploited FortiGate SSL-VPN flaw CVE-2024-21762.

Hunt.io found an open directory on server 92.63.180[.]133 holding 298 files detailing an intrusion into Triple T Broadband's 3BB brand, starting from a FortiGate 60F SSL-VPN at mail.3bb.co[.]th:10443. The actor weaponized CVE-2024-21762 (CVSS 9.8, KEV-listed since February 2024) using heap spraying and a ROP chain to gain a reverse shell. Post-exploitation included MeshCentral root-level persistence via www.ayuthayatech[.]com, Dirty COW/PwnKit privilege escalation, credential harvesting, SSH spraying against 55+ internal addresses, and log-deleting cleanup scripts; a stolen OpenVPN certificate and key from Triple T's PKI may still be valid.

Cyber Security Newsupdated · 1d agofirst · 2d agoExploit / PoC in the wild 3 sourcesCVE-2024-217622