www.securityweek.com 6/10/2026, 9:11:05 AM · external

Critical Vulnerabilities Patched in Fortinet, Ivanti Products

Critical Vulnerabilities Patched in Fortinet, Ivanti Products
Developing story vulnerability 4 articles tracked
Multiple critical vulnerabilities disclosed in Ivanti Sentry and Fortinet products
CyberSIXT Evidence Panel
Primary Source hub.ivanti.com
CISA KEV Not in KEV
Patch Patch Status Unknown

FORTINET and Ivanti released patches for critical vulnerabilities in their products, including an OS command injection flaw (CVE-2026-25089) with a CVSS score of 9.8 in Fortinet’s FortiSandbox. This vulnerability could allow unauthenticated attackers to execute arbitrary commands. Fortinet also addressed two medium-severity flaws in FortiOS and FortiProxy. Meanwhile, Ivanti patched two critical vulnerabilities in Sentry, including CVE-2026-10520 with a CVSS score of 10, allowing unauthorized remote code execution.

Ivanti’s Endpoint Manager Mobile received high-severity patches for potential remote code execution vulnerabilities. Both companies reported no evidence of these flaws being exploited in the wild.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline