Vulnerability in OpenSSL library
2026-08-29T20:52:15Z•f16db5e9c6265e87c22e0d7bf1568090fb35584b4882e1b4c50f224f13a02ffc
CVE-2022-0778CVE-2026-49975Apache-HTTP-ServerFortiAuthenticatorFortiClientFortiManagerFortiOSFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetOpenSSLPSIRTSSRFWAF-evasionXSSaccess-controlauthentication-bypassbuffer-overflowcommand-injectiondenial-of-serviceinformation-disclosureremote-code-executionvulnerability-advisories
What happened
Fortinet PSIRT feed containing multiple vulnerability advisories across FortiOS, FortiProxy, FortiWeb, FortiSIEM, FortiSandbox, FortiClient, FortiManager, FortiAuthenticator, FortiPortal, and related products. Reported impacts include unauthenticated authentication bypass, remote code and command execution, denial of service, information disclosure, access-control weaknesses, SSRF, XSS, buffer overflows, and WAF evasion. The feed also references OpenSSL CVE-2022-0778 and Apache HTTP Server CVE-2026-49975. The highest-risk entries are unauthenticated OS command injection in FortiSandbox (CVSS 9
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- f16db5e9c6265e87c22e0d7bf1568090fb35584b4882e1b4c50f224f13a02ffc
- Enrichment time
- 2026-08-29T20:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.