Vulnerability in OpenSSL library
2026-08-29T08:52:16Z•a9dc6a48b49099f982d4079c397f92172461743c2e5f4febec93b3154770ffe3
CVE-2022-0778CVE-2026-49975CWE-287CWE-305CWE-78FortiAuthenticatorFortiClientFortiManagerFortiOSFortiPAMFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetSSRFXSSaccess-controlauthentication-bypassbuffer-overflowcommand-injectiondenial-of-serviceinformation-disclosurepath-traversalremote-code-executionvulnerability-advisories
What happened
Fortinet security advisories covering multiple vulnerabilities in Fortinet products and third-party components, including unauthenticated authentication bypasses, remote code execution, command injection, memory disclosure, denial of service, access-control flaws, and web application weaknesses. The highest-risk issue is a CVSS 9.1 unauthenticated OS command injection in FortiSandbox, followed by an 8.8 FortiWeb RADIUS administrative authentication bypass and several CVSS 7.x vulnerabilities. The feed also includes OpenSSL CVE-2022-0778 and Apache HTTP Server CVE-2026-49975, both denial-ofумус
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- a9dc6a48b49099f982d4079c397f92172461743c2e5f4febec93b3154770ffe3
- Enrichment time
- 2026-08-29T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.