news.mlab.sh
Back to the feed
vulnerability

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Critical
Summary

This article reports on critical security vulnerabilities recently patched by Fortinet, Ivanti, and SAP. These vulnerabilities, including command injection and authentication bypass flaws, could allow unauthorized code execution and information disclosure. The updates are crucial for organizations using FortiSandbox, Ivanti Sentry, and various SAP products to mitigate potential risks.

Fortinet, Ivanti, and SAP have released security updates to address multiple critical vulnerabilities across their respective product lines. Fortinet patched a command injection vulnerability (CVE-2026-25089, CVSS 9.1) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. Ivanti addressed two critical flaws (CVE-2026-10520, CVSS 10.0 and CVE-2026-10523, CVSS 9.9) in Ivanti Sentry, allowing for remote code execution and administrative access. SAP released fixes for four critical vulnerabilities impacting NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, and SAP Data Hub, including XML signature wrapping and memory corruption issues. These vulnerabilities could allow attackers to gain unauthorized access to sensitive data and disrupt system operations. While there's currently no evidence of exploitation, proactive patching is strongly recommended.

Read the full article at The Hacker News