Vulnerability in OpenSSL library
2026-09-04T08:52:17Z•b9008606fa882d856fb0b6b69e7847052799283d8819fd04b55f70de76863eab
CVE-2022-0778CVE-2026-49975Apache HTTP ServerCWE-78FortiAuthenticatorFortiClientFortiManagerFortiOSFortiPAMFortiPortalFortiProxyFortiSASEFortiSIEMFortiSandboxFortiWebFortinetOpenSSLSSRFXSSauthentication-bypassbuffer-overflowcommand-injectiondenial-of-serviceimproper-access-controlinformation-disclosurepath-traversalremote-code-execution
What happened
Fortinet security advisories covering multiple products and vulnerability classes, including unauthenticated remote command execution in FortiSandbox (CVSS 9.1), authentication bypasses, access-control weaknesses, memory-safety issues, denial of service, information disclosure, XSS, SSRF, and other flaws. The feed also references CVE-2022-0778, an OpenSSL infinite-loop denial-of-service vulnerability, and CVE-2026-49975 affecting Apache HTTP Server mod_http. Several 2026 advisories have high or critical operational impact and should be prioritized for remediation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- b9008606fa882d856fb0b6b69e7847052799283d8819fd04b55f70de76863eab
- Enrichment time
- 2026-09-04T08:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.