Vulnerability in OpenSSL library
2026-09-06T20:52:17Z•4bedf53a44842c26b2af370a54854ddd345bf9510a4ff69f7961db4eb2a1aa4a
CVE-2022-0778CVE-2026-49975FortiAuthenticatorFortiClientFortiManagerFortiOSFortiPAMFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetPSIRTSSRFXSSauthentication-bypassbuffer-overflowcommand-injectiondenial-of-serviceinformation-disclosureremote-code-executionvulnerability-advisories
What happened
Fortinet PSIRT feed containing multiple product security advisories, including critical unauthenticated OS command injection in FortiSandbox (CVSS 9.1), authentication bypasses, remote code execution issues, information disclosure, denial-of-service, and web security vulnerabilities. The feed also references OpenSSL CVE-2022-0778, a certificate-parsing infinite-loop denial of service, and Apache HTTP Server CVE-2026-49975. Overall risk is high due to several remotely exploitable, unauthenticated vulnerabilities affecting Fortinet security infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- 4bedf53a44842c26b2af370a54854ddd345bf9510a4ff69f7961db4eb2a1aa4a
- Enrichment time
- 2026-09-06T20:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.