news.mlab.sh
Back to the feed
vulnerability

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

High
Summary

Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addressed a range of vulnerabilities in its security appliances and software. No exploitation of these vulnerabilities has been detected.

Fortinet, Ivanti, and ServiceNow announced the release of security updates on Tuesday to address a collection of vulnerabilities affecting their respective products. The most pressing issue involves a critical remote code execution (RCE) flaw within ServiceNow’s AI platform, identified as CVE-2026-6875, carrying a CVSS score of 9.5. ServiceNow resolved this vulnerability by deploying a security update to hosted instances, and also provided updates to self-hosted customers and partners.

Ivanti released fixes for two security defects in its data aggregation and visualization tool Xtraction, tracked as CVE-2026-14902 and CVE-2026-14903. These included a medium-severity open redirect and a high-severity path traversal, potentially allowing attackers to redirect users to malicious URLs and read files outside the web root.

Fortinet published 11 security advisories detailing 12 vulnerabilities in FortiOS, FortiProxy, FortiSASE, FortiSIEM, FortiClient EMS, FortiAuthenticator, FortiPAM, FortiSwitch Manager, FortiSwitch-Manager Agentless SSL-VPN, and FortiSandbox. These vulnerabilities ranged in severity from low to high, encompassing issues such as memory leaks, command execution, arbitrary header injection, interception and modification of authentication requests, impersonation of an AD Connector via a valid API Key, deletion of the file system, and code execution.

Fortinet stated that none of these vulnerabilities are currently being exploited in the wild. The company’s security advisories provide detailed information for remediation.

Read the full article at SecurityWeek