Vulnerability in OpenSSL library

2026-09-01T08:52:16Zd5c5ae2f811057276a7a14ff3cbda2c44c47549ca218a10adf730a99e49e0196
CVE-2022-0778CVE-2026-49975Apache HTTP ServerFortiAuthenticatorFortiClient EMSFortiManagerFortiOSFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetOpenSSLSSRFXSSaccess controlauthentication bypassbuffer overflowcommand injectiondenial of serviceimproper authenticationinformation disclosureout-of-bounds readpath traversalremote code executionvulnerability

What happened

Fortinet PSIRT feed containing multiple product vulnerabilities, including unauthenticated remote code execution in FortiSandbox (CVSS 9.1), authentication bypasses, memory-safety flaws, access-control issues, denial-of-service conditions, information disclosure, XSS, SSRF, and command injection. The feed also references OpenSSL CVE-2022-0778 and Apache HTTP Server CVE-2026-49975. Overall risk is high due to several remotely exploitable, unauthenticated vulnerabilities affecting security appliances and management platforms.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
d5c5ae2f811057276a7a14ff3cbda2c44c47549ca218a10adf730a99e49e0196
Enrichment time
2026-09-01T08:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Vulnerability in OpenSSL library · Baitaphish