Fortinet security patch release for CVE-2026-25089
Security Patch Release
Summary
Hide ▲
Show ▼
Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP products. The patches cover flaws that could lead to arbitrary code execution and information disclosure, including CVE-2026-25089 and two critical Ivanti Sentry issues. The release matters because the affected products include internet-facing and enterprise application components with high-impact exposure.
Related Happenings
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/Mitigation
H score40
First: 14.07.2026 21:17
Last: 14.07.2026 21:17
Sources 1
About this happening:
SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/MitigationAbout this happening: SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
SAP security patch release for CVE-2026-44747
Security Patch Release
H score40
First: 14.07.2026 21:17
Last: 14.07.2026 21:17
Sources 1
About this happening:
SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...
SAP security patch release for CVE-2026-44747
Security Patch ReleaseAbout this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...
SAP July 2026 security updates
Security Patch Release
H score31
First: 14.07.2026 14:42
Last: 14.07.2026 14:42
Sources 1
About this happening:
SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security updates
Security Patch ReleaseAbout this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...
SAP July 2026 security patch day
Security Patch Release
H score40
First: 14.07.2026 14:17
Last: 14.07.2026 14:17
Sources 1
About this happening:
SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
SAP July 2026 security patch day
Security Patch ReleaseAbout this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...
Splunk Enterprise security update for CVE-2026-20253
Security Patch Release
H score52
First: 13.06.2026 16:23
Last: 13.06.2026 16:23
Sources 1
About this happening:
Splunk released security updates for CVE-2026-20253, fixing a critical Splunk Enterprise flaw that could enable unauthenticated file operations and remote code e...
Splunk Enterprise security update for CVE-2026-20253
Security Patch ReleaseAbout this happening: Splunk released security updates for CVE-2026-20253, fixing a critical Splunk Enterprise flaw that could enable unauthenticated file operations and remote code e...
Timeline
-
11.06.2026 09:20 1 articles · 1mo ago
Shadowserver observes CVE-2026-10520 exploitation of Ivanti Sentry gateways
Exploitation ObservedShadowserver reported large-scale exploitation attempts against Internet-exposed Ivanti Sentry gateways after CVE-2026-10520 was patched in R10.5.2, R10.6.2, and R10.7.1, saying it saw 19 vulnerable instances and at least 2 backdoored systems and warning that unpatched devices were most likely compromised.
Show sources
- Max severity Ivanti Sentry vulnerability now exploited in attacks — www.bleepingcomputer.com — 11.06.2026 09:20
-
10.06.2026 18:10 1 articles · 1mo ago
Ivanti Sentry fixes block root-level remote code execution
Mitigation Patch UpdateIvanti published fixes for Ivanti Sentry (formerly MobileIron Sentry) to address CVE-2026-10520, an operating system command injection issue that could let a remote unauthenticated user achieve root-level remote code execution, and CVE-2026-10523, an authentication bypass flaw that could let a remote unauthenticated attacker create arbitrary administrative accounts and gain full administrative access; the update adds controls that block access to the vulnerable endpoint and redirect unauthenticated requests to the login page.
Show sources
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — thehackernews.com — 10.06.2026 18:10
-
10.06.2026 18:10 2 articles · 1mo ago
Fortinet FortiSandbox fixes close command injection flaw
Mitigation Patch UpdateFortinet released security updates for FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI to address CVE-2026-25089, a command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized commands through specially crafted HTTP requests; affected versions include FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
Show sources
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — thehackernews.com — 10.06.2026 18:10
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — thehackernews.com — 10.06.2026 18:10
-
10.06.2026 18:10 1 articles · 1mo ago
SAP fixes close critical flaws across NetWeaver, Commerce Cloud, and Data Hub
Mitigation Patch UpdateSAP pushed out fixes for CVE-2026-44748, CVE-2026-27671, CVE-2026-22732, and CVE-2026-40128 affecting SAP NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, SAP Data Hub, and SAP NetWeaver Application Server Java; the issues include XML signature wrapping in SAML authentication, memory corruption in the ABAP application server, a potential Spring security issue, and directory traversal in the Java web container.
Show sources
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — thehackernews.com — 10.06.2026 18:10