Multiples vulnérabilités dans les produits Fortinet (11 septembre 2026)
Multiple vulnerabilities have been discovered in Fortinet products, including potential data integrity and confidentiality breaches, denial of service attacks, and remote code execution. These vulnerabilities allow an attacker to execute arbitrary code, elevate privileges, and cause a denial of service. Several CVEs have been assigned, including CVE-2026-22575, CVE-2026-26084, CVE-2026-84385, CVE-2026-84386, CVE-2026-84387, CVE-2026-84388, CVE-2026-84389, and CVE-2026-84390. Users are advised to consult Fortinet's security bulletins for available patches.
A security advisory from CERT-FR details multiple vulnerabilities impacting various Fortinet products. These vulnerabilities could lead to data integrity and confidentiality breaches, as well as the ability to execute code remotely and cause denial of service attacks. Specifically, affected products include FortiAnalyzer, FortiClientWindows, FortiManager Cloud, FortiManager, FortiMonitorOnSight, FortiPAM Chrome Extension, FortiPAM, FortiProxy, FortiSandbox Cloud, FortiSandbox PaaS, FortiSandbox, FortiSIEM, and FortiSOAR on-premise. The vulnerabilities are detailed in a series of security bulletins released by Fortinet. Several CVE identifiers have been assigned, including CVE-2026-22575, CVE-2026-26084, CVE-2026-84385, CVE-2026-84386, CVE-2026-84387, CVE-2026-84388, CVE-2026-84389, and CVE-2026-84390. Users are strongly encouraged to review and apply the recommended patches from Fortinet's security bulletins to mitigate these risks. The bulletins provide detailed information on how to address these vulnerabilities and maintain system security.