Fortinet FortiOS Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CVSS Score
9.8
CRITICAL
Published
27 Jul 2026 00:00
Modified
N/A
Vendor
Fortinet
Product
FortiOS
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-200
Affected Systems
Fortinet
FortiOS
Fortinet
FortiOS
FortiSandbox
External Links
KEV Status
Known Exploited Vulnerability