Vulnerability in OpenSSL library
2026-09-01T08:52:16Z•d5c5ae2f811057276a7a14ff3cbda2c44c47549ca218a10adf730a99e49e0196
CVE-2022-0778CVE-2026-49975Apache HTTP ServerFortiAuthenticatorFortiClient EMSFortiManagerFortiOSFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetOpenSSLSSRFXSSaccess controlauthentication bypassbuffer overflowcommand injectiondenial of serviceimproper authenticationinformation disclosureout-of-bounds readpath traversalremote code executionvulnerability
What happened
Fortinet PSIRT feed containing multiple product vulnerabilities, including unauthenticated remote code execution in FortiSandbox (CVSS 9.1), authentication bypasses, memory-safety flaws, access-control issues, denial-of-service conditions, information disclosure, XSS, SSRF, and command injection. The feed also references OpenSSL CVE-2022-0778 and Apache HTTP Server CVE-2026-49975. Overall risk is high due to several remotely exploitable, unauthenticated vulnerabilities affecting security appliances and management platforms.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- d5c5ae2f811057276a7a14ff3cbda2c44c47549ca218a10adf730a99e49e0196
- Enrichment time
- 2026-09-01T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.