Fortinet
Vulnerabilities in FortiOS, FortiGate, and FortiProxy — the firewall and SSL-VPN appliances that sit at the network edge, making a single auth-bypass or overflow bug a direct path to full network compromise.
Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)
An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
Fortinet FortiSandbox unauthenticated OS command injection (4.4 branch and PaaS)
An unauthenticated OS command injection in Fortinet FortiSandbox 4.4.0–4.4.8 and a range of FortiSandbox PaaS builds lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.
FortiOS / FortiProxy Authentication Bypass on Administrative Interface
An authentication-bypass vulnerability in FortiOS, FortiProxy, and FortiSwitchManager allows a remote attacker to perform administrative operations on the management interface via crafted HTTP(S) requests, including adding a new administrator SSH key for persistent access.

FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline
CISA added CVE-2026-39808 and CVE-2026-25089 to KEV today — unauthenticated OS command injection in Fortinet FortiSandbox, CVSS 9.8 each, federal BOD 26-04 deadline this Sunday.

FortiOS Auth Bypass: Fortinet Warned Select Customers
CVE-2022-40684 let attackers bypass authentication on FortiOS and FortiProxy management interfaces and plant persistent SSH keys — Fortinet quietly warned targeted customers before public disclosure.