Fortinet FortiOS follow-on patch release for authentication bypass
Security Patch Release
Summary
Hide ▲
Show ▼
Fortinet is preparing FortiOS 7.4.11, 7.6.6, and 8.0.0 to fully close an authentication bypass flaw affecting FortiOS/FortiGate deployments. The follow-on release matters because earlier updates were reported to have left the issue only partially fixed. The planned fixes are expected over the coming days.
Related Happenings
Fortinet security patch release for CVE-2026-44277
Security Patch Release
First: 12.05.2026 21:23
Last: 12.05.2026 21:23
Sources 1
About this happening:
Fortinet released **security updates** for **FortiSandbox** and **FortiAuthenticator** to fix **two critical vulnerabilities** that could let an **unauthenticated attacker** execu...
Fortinet security patch release for CVE-2026-44277
Security Patch ReleaseAbout this happening: Fortinet released **security updates** for **FortiSandbox** and **FortiAuthenticator** to fix **two critical vulnerabilities** that could let an **unauthenticated attacker** execu...
SAP security patch release for CVE-2019-17571
Security Patch Release
First: 11.03.2026 14:26
Last: 11.03.2026 14:26
Sources 1
About this happening:
**SAP** released security updates for **two critical flaws** in **FS-QUO** and **NetWeaver Enterprise Portal Administration**, reducing the risk of **arbitrary code execution** on...
SAP security patch release for CVE-2019-17571
Security Patch ReleaseAbout this happening: **SAP** released security updates for **two critical flaws** in **FS-QUO** and **NetWeaver Enterprise Portal Administration**, reducing the risk of **arbitrary code execution** on...
Fortinet FortiClientEMS security update for CVE-2026-21643
Security Patch Release
First: 10.02.2026 06:38
Last: 10.02.2026 06:38
Sources 1
About this happening:
Fortinet released **security updates** for **FortiClientEMS** to fix **CVE-2026-21643**, a critical **SQL injection** flaw that could let an **unauthenticated attacker** execute a...
Fortinet FortiClientEMS security update for CVE-2026-21643
Security Patch ReleaseAbout this happening: Fortinet released **security updates** for **FortiClientEMS** to fix **CVE-2026-21643**, a critical **SQL injection** flaw that could let an **unauthenticated attacker** execute a...
Fortinet security patch release for CVE-2026-24858
Security Patch Release
First: 28.01.2026 06:49
Last: 28.01.2026 06:49
Sources 1
About this happening:
**Fortinet** began releasing **security updates** for **CVE-2026-24858**, a critical **FortiOS** authentication-bypass flaw that also affects **FortiManager** and **FortiAnalyzer*...
Fortinet security patch release for CVE-2026-24858
Security Patch ReleaseAbout this happening: **Fortinet** began releasing **security updates** for **CVE-2026-24858**, a critical **FortiOS** authentication-bypass flaw that also affects **FortiManager** and **FortiAnalyzer*...
Fortinet FortiCloud SSO mitigation guidance
Advisory/Mitigation
First: 28.01.2026 01:19
Last: 28.01.2026 01:19
Sources 1
About this happening:
**Fortinet** advised customers to **restrict administrative access** and **disable FortiCloud SSO** to reduce abuse of an **actively exploited** authentication bypass affecting de...
Fortinet FortiCloud SSO mitigation guidance
Advisory/MitigationAbout this happening: **Fortinet** advised customers to **restrict administrative access** and **disable FortiCloud SSO** to reduce abuse of an **actively exploited** authentication bypass affecting de...
Timeline
-
21.01.2026 19:49 3 articles · 4mo ago
Fortinet plans follow-on FortiOS fixes for CVE-2025-59718
Mitigation Patch UpdateFortinet is reportedly preparing FortiOS 7.4.11, 7.6.6, and 8.0.0 over the coming days to fully patch CVE-2025-59718 after earlier FortiOS 7.4.9 and 7.4.10 updates were said to leave the authentication bypass incomplete. FortiGate admins running 7.4.9/7.4.10 reported malicious SSO logins that created local admin access, reinforcing the need for the follow-on release.
Show sources
- Fortinet admins report patched FortiGate firewalls getting hacked — www.bleepingcomputer.com — 21.01.2026 19:49
- Fortinet admins report patched FortiGate firewalls getting hacked — www.bleepingcomputer.com — 21.01.2026 19:49
- Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls — thehackernews.com — 23.01.2026 14:30