Fortinet Patches Multiple Products for Critical Flaws
ANSSI advisory details multiple vulnerabilities across Fortinet products including FortiOS, FortiWeb, FortiManager and FortiClient enabling RCE, privilege escalation and DoS.
CERT-FR published an advisory covering multiple vulnerabilities affecting a broad range of Fortinet products, including FortiClient for Windows, FortiManager, FortiManager Cloud, FortiOS, FortiPAM, FortiProxy, FortiSIEM, FortiSwitchManager, and FortiWeb. The flaws span several vulnerability classes: remote code execution, privilege escalation, remote denial of service, SSRF, security policy bypass, and confidentiality breaches, indicating a diverse set of underlying issues rather than a single root cause.
Eight distinct Fortinet PSIRT bulletins (FG-IR-26-156 through FG-IR-26-163) map to eight CVEs disclosed on 12 August 2026. No indication of active exploitation is provided in the advisory, and no threat actor or campaign is attributed. Given the wide product footprint—spanning network security appliances, SIEM, PAM, and endpoint client software—organizations running affected Fortinet versions should prioritize patching per vendor guidance, particularly for internet-facing management interfaces such as FortiManager and FortiProxy.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1015
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free