Fortinet Fixes Wide Patch Set Across Forti Stack

NCSC-NL says Fortinet fixed multiple vulnerabilities today across FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitorOnSight, FortiClient Windows, FortiSIEM, and FortiSOAR. The most severe is CVE-2026-26084 in FortiSandbox, which NCSC-NL describes as an authorization flaw with a CVSS score of 9.9. The other fixes span several flaw types, including command injection, unverified ownership, certificate-validation failure, uninitialized-variable use, null-pointer dereference, sensitive-information exposure in source code, and open redirect. Fortinet’s update set matters because a single environment may carry several exposed management or endpoint components at once, so the exposure is not limited to one box. For shops that run multiple Forti products, the story is less about one product line than about shared control-plane risk across the stack. What remains after the patches is the question of which Forti components are present and reachable in each estate, since the advisory covers several families but not one uniform failure mode.

Part of the PlainSec briefing for 2026-09-09

Editions

Sources