Arbitrary process termination from exposed minifilter communication port

2026-09-14T08:52:16Z•50b7fb8c09246f3d7a70e79f55bd4bde5466abda2504509517d9d9f8a42c9a04
CVE-2022-0778CVE-2026-49975CWEFortiClientFortiManagerFortiMonitorOnSightFortiOSFortiPAMFortiProxyFortiSIEMFortiSandboxFortiWebFortinetPSIRTauthentication-bypasscertificate-validationdenial-of-serviceimproper-access-controlinformation-disclosureremote-code-executionvulnerability-advisories

What happened

Fortinet PSIRT advisories covering multiple Fortinet products, including critical authentication bypasses, unauthenticated access-control flaws, remote code execution, information disclosure, denial of service, certificate-validation weaknesses, and web application vulnerabilities. The highest-impact issues include FortiMonitorOnSight JWT authentication bypass (CVSS 9.6), FortiPAM browser traffic proxying (CVSS 9.1), FortiSandbox sensitive-information exposure (CVSS 8.9), and FortiWeb RADIUS authentication bypass (CVSS 8.8). The feed also references OpenSSL CVE-2022-0778 and Apache HTTP Server

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
50b7fb8c09246f3d7a70e79f55bd4bde5466abda2504509517d9d9f8a42c9a04
Enrichment time
2026-09-14T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.