Arbitrary process termination from exposed minifilter communication port
2026-09-16T20:52:17Z•dbc5f75f3dfccfd21908ad83ff0870da34ba61ad5d63a6b08ec97b06198cb27b
CVE-2022-0778CVE-2026-49975CWE-120CWE-284CWE-287CWE-295CWE-476CWE-77CWE-918FortinetPSIRTWAF-evasionauthentication-bypassbuffer-overflowcertificate-validationcommand-injectiondenial-of-serviceimproper-access-controlmultiple-vulnerabilitiesremote-code-executionsensitive-information-disclosure
What happened
Fortinet PSIRT advisories disclose numerous vulnerabilities across FortiOS, FortiProxy, FortiClient, FortiManager, FortiSandbox, FortiSIEM, FortiWeb, FortiPAM, FortiMonitorOnSight, FortiAnalyzer, FortiAuthenticator, FortiSOAR, FortiSASE, and related components. Impacts include unauthenticated authentication bypass, remote code execution, sensitive information disclosure, denial of service, man-in-the-middle attacks, access-control bypass, SSRF, WAF evasion, and arbitrary process termination. The highest-risk issues are forged JWT authentication bypass in FortiMonitorOnSight (CVSS 9.6), FortiP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- dbc5f75f3dfccfd21908ad83ff0870da34ba61ad5d63a6b08ec97b06198cb27b
- Enrichment time
- 2026-09-16T20:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.