Showing posts with label FortiGuard. Show all posts
Showing posts with label FortiGuard. Show all posts

Thursday, September 10, 2026

CISA Adds FortiGuard Vulnerability to KEV Catalog – 9-9-26

Yesterday, CISA announced that it had added a heap-based buffer overflow vulnerability in the FortiGuard FortiOS and FortiSwitchManager products to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard published their advisory on the vulnerability in January 2026, and most recently updated it in February. Fixed versions are available. 

On Tuesday, SOCRadar published an article detailing their discovery of the “PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool.” They report seeing evidence of exploits in the wild as far back as July of this year. The article provides a detailed technical analysis of the fortirun.bin component of PivotC2 as well as indicators of compromise. 

CISA has directed federal agencies using the affected FortiGuard products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance deadline of September 12th, 2026 has been established. 

Monday, July 27, 2026

CISA Adds FortiGuard Advisory to KEV Catalog – 7-27-26

This afternoon, CISA announced that it had added an exposure of sensitive information to an unauthorized actor vulnerability in the FortiGuard FortiOS product to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard reported the vulnerability on February 10th, 2026, and updated that advisory on March 12th, 2026. That advisory notes that: “Products that never had SSL-VPN enabled, are not impacted by this issue.”  

The vulnerability was originally reported by Peter Gabaldon from ITRESIT; that report includes proof-of-concept code. Gabaldon published additional information on the vulnerability discovery here. A separate exploit for the vulnerability was published by indoushka on February 16th, 2026. 

CISA has directed federal agencies using the affected FortiOS products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [Links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” A compliance deadline of August 10th, 2026, has been set. 

Friday, July 17, 2026

CISA Adds 2 FortiGuard Vulnerabilities to KEV Catalog – 7-16-26

Yesterday, CISA announced that it had added two OS command injection vulnerabilities in the FortiGuard FortiSandbox product to the Known Exploited Vulnerabilities (KEV) catalog. 

CVE-2026-25089 – This vulnerability was previously reported by FortiGuard in June. FortiGuard has new versions that mitigate the vulnerability. 

CVE-2026-39808 – This vulnerability was previously reported by FortiGuard in April. FortiGuard has a new version that mitigates the vulnerability. The vulnerability was originally reported by Samuel de Lucas Maroto from KPMG Spain. Proof-of-concept code was published by Samu DeLucas on April 15th, 2026. 

CISA has directed federal agencies using the FortiSandbox product to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. A compliance deadline of July 19th, 2026 has been established. 

Monday, June 22, 2026

Review - Public ICS Disclosures – Week of 6-13-26 – Part 3

For Part 3 we have 10 vendor updates from CODESYS (4), D-Link (2), FortiGuard, HP, Moxa (2). There are two researcher reports for vulnerabilities in products from Phoenix Contact and Sprecher Automation. Finally, we have two exploits for products from D-Link and Genetec. 

Updates  

CODESYS Update #1 - CODESYS published an update for their Auditlog advisory that was originally published on March 24th, 2026. 

CODESYS Update #2 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Update #3 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Updte #4 - CODESYS published an update for their Control V3 advisory that was originally puublished on March 24th, 2026. 

D-Link Advisory #1 - D-Link published an update for their DWR-921 advisory that was originally published on April 22nd, 2021.  

D-Link Advisory #2 - D-Link published an update for their DCS-935L advisory that was originally published on September 12th, 2025. 

FortiGuard Update - FortiGuard published an update for their FortiOS advisory that was originally published on June 10th, 2025. 

HP Update - HP published an update for their Intel Chipset advisory that was originally published on October 17th, 2025, and most recently updated on March 19th, 2026. 

Moxa Update #1 - Moxa published an update for their Linux Kernel advisory that was originally published on May 26th, 2026. 

Moxa Update #2 - Moxa published an update for their NPort 5000 Series advisory that was originally published on October 3rd, 2023, and most recently updated on October 23rd, 2023. 

Researcher Reports  

Phoenix Contact Report - Nozomi Networks published a report that describes six vulnerabilities in the Phoenix Contact PLCnext product. 

Sprecher Report - SEC Consult published a report that describes seven vulnerabilities in the Sprecher SPRECON-E-C/-E-P/-E-T3 systems. 

Exploits  

D-Link Exploit - Indoushka published an exploit for a privlege escalation vulnerability in the D-Link DSL2600U routers. 

Genetec Exploit - Indoushka published an exploit for for an incorrect permission assignement for criitical resource vulnerability in the Genetec RabbitMQ. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-ce6 - subscription required. 

 
/* Use this with templates/template-twocol.html */