Arbitrary process termination from exposed minifilter communication port

2026-09-23T20:52:16Z•dad836f0e160778f2d0b117ee4c8f44843fcf9172899353f1b1e53800da76f84
CVE-2022-0778CVE-2026-49975FortiAnalyzerFortiAuthenticatorFortiClientFortiManagerFortiMonitorOnSightFortiOSFortiPAMFortiProxyFortiSIEMFortiSOARFortiSandboxFortiWebFortinetPSIRTWAF-evasionaccess-controlauthentication-bypassbuffer-overflowcertificate-validationcommand-injectiondenial-of-serviceinformation-disclosureremote-code-execution

What happened

Fortinet PSIRT advisories disclose numerous vulnerabilities across FortiOS, FortiProxy, FortiClient, FortiManager, FortiSandbox, FortiWeb, FortiSIEM, FortiAuthenticator, FortiPAM, FortiMonitorOnSight, FortiAnalyzer, FortiSOAR and related products. Impacts include unauthenticated authentication bypass, remote code execution, sensitive information disclosure, man-in-the-middle attacks, access-control bypass, denial of service, command injection, SSRF, buffer overflows, and WAF evasion. The highest-risk issues are JWT authentication bypass in FortiMonitorOnSight (CVSS 9.6), FortiPAM improper una�

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
dad836f0e160778f2d0b117ee4c8f44843fcf9172899353f1b1e53800da76f84
Enrichment time
2026-09-23T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.