Arbitrary process termination from exposed minifilter communication port

2026-09-19T08:52:16Z•614c369b14d3515cad4c62439767b8e9ef2bd179580d00f31da13de6c12df7bc
CVE-2022-0778CVE-2026-49975Apache HTTP ServerFortinetOpenSSLPSIRTSSRFWAF-evasionXSSauthentication-bypassbuffer-overflowcertificate-validationcommand-injectiondenial-of-serviceimproper-access-controlinformation-disclosureremote-code-executionvulnerability-disclosure

What happened

Fortinet PSIRT advisories covering multiple vulnerabilities across FortiClient, FortiSOAR, FortiSandbox, FortiPAM, FortiMonitorOnSight, FortiOS, FortiProxy, FortiSIEM, FortiAnalyzer, FortiManager, FortiWeb, FortiSASE, FortiAuthenticator, and related products. Issues range from low-severity denial of service and open redirect flaws to critical authentication bypass, sensitive information disclosure, arbitrary code execution, and unauthenticated administrative access. The feed also includes third-party vulnerabilities CVE-2022-0778 in OpenSSL and CVE-2026-49975 in Apache HTTP Server.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
614c369b14d3515cad4c62439767b8e9ef2bd179580d00f31da13de6c12df7bc
Enrichment time
2026-09-19T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.