Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products.
The addressed vulnerabilities could allow the attacker to bypass authentication mechanisms, perform denial-of-service attacks, execute unauthorized code or commands, gain elevated privileges, obtain sensitive information, bypass firewall and access control policies, or gain unauthorized administrative access to the affected products.
Sample of the addressed vulnerabilities:
1. FortiSwitchAX Buffer Overflow in LLDP OUI field Vulnerability (CVE-2026- 22627):
2. FortiClientLinux Local Privilege Escalation Vulnerability (CVE-2026-24018):
It should be highlighted that Cybersecurity researchers have discovered a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks through previously disclosed vulnerabilities that have already been patched, “CVE-2025-59718, CVE- 2025-59719, and CVE-2026-24858”.
The enterprise should deploy this patch as soon as the testing phase is completed.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |