Monday, July 27, 2026

CISA Adds FortiGuard Advisory to KEV Catalog – 7-27-26

This afternoon, CISA announced that it had added an exposure of sensitive information to an unauthorized actor vulnerability in the FortiGuard FortiOS product to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard reported the vulnerability on February 10th, 2026, and updated that advisory on March 12th, 2026. That advisory notes that: “Products that never had SSL-VPN enabled, are not impacted by this issue.”  

The vulnerability was originally reported by Peter Gabaldon from ITRESIT; that report includes proof-of-concept code. Gabaldon published additional information on the vulnerability discovery here. A separate exploit for the vulnerability was published by indoushka on February 16th, 2026. 

CISA has directed federal agencies using the affected FortiOS products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [Links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of August 10th, 2026, has been set. 

No comments:

 
/* Use this with templates/template-twocol.html */