Wednesday , September 9 2026
FortiGate

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access trojan (RAT). This makes the affected devices key points for spying and stealing information.

The SOCRadar Threat Research Unit has found that attackers are using CVE-2025-25249. This is a serious flaw in the cw_acd daemon in FortiOS and FortiSwitchManager.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Rated 9.8 on the CVSSv3 scale, this weakness lets attackers from afar run any code they want by sending special requests to the CAPWAP Control service, which is found on UDP port 5246.

Fortinet uses CAPWAP to control wireless access points from one place. This makes the system available on many FortiGate devices that connect to the internet. The affected versions include FortiOS 6.4 to 7.6.3 and FortiSwitchManager 7.0.x and 7.2.x, but Fortinet released fixes after the news was shared on January 13, 2026.

Administrators should limit outside access to CAPWAP Control ports, look for strange Node.js processes and files like /tmp/.i.js on open devices, and review active sessions for links to known bad IP addresses.

Because PivotC2 collects device settings in bulk, any group that sees hints of a breach should consider all saved passwords, like SSL-VPN, LDAP, and IPSec keys, to be unsafe and change them right away.

FortiSandbox Vulnerability

Fortinet has revealed a serious vulnerability in its FortiSandbox platform. It warn that attackers without permission could take advantage of issues in the web interface to steal sensitive information without needing valid logins.

The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.

FortiOS and FortiProxy ZTNA Validation Vulnerabilit:

Fortinet has revealed a serious flaw with certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. This issue could allow an unauthorized remote attacker to intercept traffic between the ZTNA portal and the website it connects to.

Tracked as CVE-2026-84393 and noted in advisory FG-IR-26-174, the flaw was released on September 8, 2026, and has a CVSSv3 score of 7.3. The weakness comes from a flawed certificate check, classified as CWE-295, in the Agentless ZTNA portal part. Zero Trust Network Access portals aim to create safe connections with identity checks between users and internal apps without needing a complete VPN client.

Check Also

Dahua

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day …