Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP
2026-04-15T19:24:00Z•bd7be8511fb241047437ca9372efd741eec0fda628cd101619cd3b87c87c1688
AI agentsAdobe Acrobat/ReaderAnthropicAutovistaAxiosBasic-FitBooking.comCISACPUIDExcelFortinetGitHub ActionsMicrosoftMythos/Project GlasswingPatch TuesdayTrivyactive exploitationauthentication bypasscredential theftprompt injectionransomwareremote code executionsandboxsupply chain compromisezero-day
What happened
A high-severity security roundup from The Register covering multiple active and critical incidents: two critical Fortinet sandbox vulnerabilities that can allow unauthenticated authentication bypass and remote command execution over HTTP; a 17-year-old critical Microsoft Excel flaw now under active exploitation (on CISA's exploited list); a months-old zero-day in Adobe Acrobat/Reader used to profile victims; and Microsoft’s large Patch Tuesday that included at least one actively exploited CVE. The feed also highlights widespread supply-chain and agent risks (Trivy/Axios supply-chain incidents,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- bd7be8511fb241047437ca9372efd741eec0fda628cd101619cd3b87c87c1688
- Enrichment time
- 2026-04-15T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.