Signal

Fortinet patches multiple critical vulnerabilities including remote code execution flaws

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-12 07:00 UTCUpdated 2026-05-13 09:36 UTC
rss
cveexploitssecurity_toolingincident_responsesecurity_policy
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
FortiNDR: CVSS (Max): 5.1
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 02:10 UTC
limited source diversity in top sources
Overview

Fortinet has released security advisories addressing several vulnerabilities across its product portfolio, including critical remote code execution (RCE) flaws in FortiSandbox and FortiAuthenticator.

Entities
FortinetFortiSandboxFortiAuthenticatorFortiAPFortiOSFortiMailFortiNDRFortiTokenAndroid
Score total
1.92
Momentum 24h
14
Posts
14
Origins
5
Source types
1
Duplicate ratio
0%
Why now
  • Fortinet published multiple security advisories on May 12-13, 2026, with patches now available.
  • Several vulnerabilities have high CVSS scores indicating severe risk if exploited.
  • Security centers and advisories are actively urging users to update affected products immediately.
Why it matters
  • Fortinet products are widely deployed in enterprise networks, making these vulnerabilities significant for many organizations.
  • Critical remote code execution flaws could allow attackers to fully compromise affected systems.
  • Timely patching is essential to prevent exploitation and potential data breaches.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Fortinet products have multiple vulnerabilities that could allow remote code execution.
  • Critical patches have been released for FortiAuthenticator, FortiSandbox, FortiOS, and other Fortinet products.
How sources frame it
  • CIS Security Advisories: neutral
  • Canadian Centre For Cyber Security: neutral
  • Sergiu Gatlan, BleepingComputer: neutral
Consolidated multiple Fortinet vulnerability advisories into a single briefing highlighting critical RCE flaws and patch availability.
All evidence
All evidence
Fortinet, Ivanti Patch Critical Vulnerabilities
SecurityWeek · securityweek.com · 2026-05-13 09:36 UTC
FortiNDR: CVSS (Max): 5.1
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 02:10 UTC
FortiMail: CVSS (Max): 6.3
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 02:10 UTC
FortiOS: CVSS (Max): 8.3
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 02:09 UTC
FortiTokenAndroid: CVSS (Max): 5.0
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 02:09 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 5 / 0
Top publishers (this list)
  • AusCERT - Bulletins (4)
  • SecurityWeek (1)
Top origin domains (this list)
  • portal.auscert.org.au (4)
  • securityweek.com (1)