Vulnerability in OpenSSL library

2026-08-29T20:52:15Zf16db5e9c6265e87c22e0d7bf1568090fb35584b4882e1b4c50f224f13a02ffc
CVE-2022-0778CVE-2026-49975Apache-HTTP-ServerFortiAuthenticatorFortiClientFortiManagerFortiOSFortiPortalFortiProxyFortiSIEMFortiSandboxFortiWebFortinetOpenSSLPSIRTSSRFWAF-evasionXSSaccess-controlauthentication-bypassbuffer-overflowcommand-injectiondenial-of-serviceinformation-disclosureremote-code-executionvulnerability-advisories

What happened

Fortinet PSIRT feed containing multiple vulnerability advisories across FortiOS, FortiProxy, FortiWeb, FortiSIEM, FortiSandbox, FortiClient, FortiManager, FortiAuthenticator, FortiPortal, and related products. Reported impacts include unauthenticated authentication bypass, remote code and command execution, denial of service, information disclosure, access-control weaknesses, SSRF, XSS, buffer overflows, and WAF evasion. The feed also references OpenSSL CVE-2022-0778 and Apache HTTP Server CVE-2026-49975. The highest-risk entries are unauthenticated OS command injection in FortiSandbox (CVSS 9

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
f16db5e9c6265e87c22e0d7bf1568090fb35584b4882e1b4c50f224f13a02ffc
Enrichment time
2026-08-29T20:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.