< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Fortinet and SolarWinds issue patches for critical security vulnerabilities

Fortinet has identified two critical vulnerabilities in its FortiOS and FortiProxy software. CVE-2024-21762, which carries a CVSS score of 9.6, involves improper parameter validation in the SSL-VPN and is reportedly being exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog. The second flaw, CVE-2024-23113, has a CVSS score of 9.8 and stems from a format string vulnerability in the fgfm daemon.

Separately, SolarWinds released security updates to address a high-severity flaw in its Access Rights Manager (ARM). Tracked as CVE-2026-28326 with a CVSS score of 8.8, the vulnerability is caused by a hard-coded static key that could allow unauthenticated remote code execution. SolarWinds has also patched multiple flaws in its Serv-U and Web Help Desk products to prevent privilege escalation and denial-of-service attacks.

Entities

CISA · Fortinet · SolarWinds