started · updated
Fortinet and SolarWinds issue patches for critical security vulnerabilities
Fortinet has identified two critical vulnerabilities in its FortiOS and FortiProxy software. CVE-2024-21762, which carries a CVSS score of 9.6, involves improper parameter validation in the SSL-VPN and is reportedly being exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog. The second flaw, CVE-2024-23113, has a CVSS score of 9.8 and stems from a format string vulnerability in the fgfm daemon.
Separately, SolarWinds released security updates to address a high-severity flaw in its Access Rights Manager (ARM). Tracked as CVE-2026-28326 with a CVSS score of 8.8, the vulnerability is caused by a hard-coded static key that could allow unauthenticated remote code execution. SolarWinds has also patched multiple flaws in its Serv-U and Web Help Desk products to prevent privilege escalation and denial-of-service attacks.
Entities
CISA · Fortinet · SolarWinds