Arbitrary process termination from exposed minifilter communication port
2026-09-19T08:52:16Z•614c369b14d3515cad4c62439767b8e9ef2bd179580d00f31da13de6c12df7bc
CVE-2022-0778CVE-2026-49975Apache HTTP ServerFortinetOpenSSLPSIRTSSRFWAF-evasionXSSauthentication-bypassbuffer-overflowcertificate-validationcommand-injectiondenial-of-serviceimproper-access-controlinformation-disclosureremote-code-executionvulnerability-disclosure
What happened
Fortinet PSIRT advisories covering multiple vulnerabilities across FortiClient, FortiSOAR, FortiSandbox, FortiPAM, FortiMonitorOnSight, FortiOS, FortiProxy, FortiSIEM, FortiAnalyzer, FortiManager, FortiWeb, FortiSASE, FortiAuthenticator, and related products. Issues range from low-severity denial of service and open redirect flaws to critical authentication bypass, sensitive information disclosure, arbitrary code execution, and unauthenticated administrative access. The feed also includes third-party vulnerabilities CVE-2022-0778 in OpenSSL and CVE-2026-49975 in Apache HTTP Server.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- 614c369b14d3515cad4c62439767b8e9ef2bd179580d00f31da13de6c12df7bc
- Enrichment time
- 2026-09-19T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.