<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>FortiProxy (Versions 7.4.x Antérieures À 7.4.11) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fortiproxy-versions-7.4.x-ant%C3%A9rieures-%C3%A0-7.4.11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 14 Jun 2026 09:12:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fortiproxy-versions-7.4.x-ant%C3%A9rieures-%C3%A0-7.4.11/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure</title><link>https://feed.craftedsignal.io/briefs/2026-06-fortinet-multi-vuln/</link><pubDate>Sun, 14 Jun 2026 09:12:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-06-fortinet-multi-vuln/</guid><description>Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.</description><content:encoded><![CDATA[<p>Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been identified across various Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox. These flaws, detailed in Fortinet security bulletins FG-IR-26-140, FG-IR-26-141, and FG-IR-26-143 issued on June 9, 2026, could allow an unauthenticated attacker to achieve remote arbitrary code execution (RCE) and compromise data confidentiality. CERT-FR published an advisory (CERTFR-2026-AVI-0725) on June 10, 2026, urging immediate patching. The widespread deployment of Fortinet products in enterprise networks makes these vulnerabilities high-impact, as successful exploitation could lead to full system compromise, network breaches, and sensitive data exposure without prior authentication.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker identifies a vulnerable Fortinet product (e.g., FortiOS, FortiPortal, FortiProxy, FortiSandbox) exposed to the internet.</li>
<li>The attacker crafts and sends a malicious HTTP request targeting the specific vulnerability (CVE-2025-67862, CVE-2026-25089, or CVE-2026-49938).</li>
<li>The vulnerable Fortinet product processes the malformed request, triggering the underlying vulnerability, potentially in a web-facing component.</li>
<li>Successful exploitation of RCE vulnerabilities (CVE-2026-25089, CVE-2026-49938) allows the attacker to execute arbitrary commands on the underlying operating system of the appliance.</li>
<li>With RCE, the attacker gains full control over the compromised Fortinet device, enabling them to establish persistence or deploy further malicious payloads.</li>
<li>The attacker can then use the compromised device as a pivot point to move laterally within the network or access sensitive data, leveraging data confidentiality vulnerabilities (CVE-2025-67862) to exfiltrate information.</li>
<li>The final objective could range from network reconnaissance, further system compromise, data theft, or disruption of network services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The identified vulnerabilities pose a critical risk to organizations utilizing affected Fortinet products. Successful exploitation, particularly of the RCE flaws, could lead to full compromise of the Fortinet appliance itself, granting attackers a foothold within the perimeter network. This could facilitate unauthorized access to internal systems, network segmentation bypasses, and the deployment of additional malware such as backdoors or ransomware. Data confidentiality breaches could result in the exposure of sensitive network configurations, user credentials, or other critical business data, potentially leading to significant financial loss, reputational damage, and regulatory penalties. The widespread use of Fortinet products globally means a broad array of organizations across various sectors could be susceptible.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately apply the security patches provided by Fortinet for all affected products listed in this brief (FortiOS &lt; 7.2.11, FortiPortal &lt; 7.4.8, FortiProxy &lt; 7.2.15, FortiSandbox &lt; 5.0.6, etc.) to address CVE-2025-67862, CVE-2026-25089, and CVE-2026-49938.</li>
<li>Deploy the provided Sigma rules &quot;Detects CVE-2026-25089/49938 Exploitation Attempts - Suspicious HTTP Request Patterns&quot; and &quot;Detects CVE-2025-67862 Exploitation Attempts - Unusual HTTP Access to Sensitive Paths&quot; to your SIEM to detect potential exploitation attempts.</li>
<li>Ensure web server logging is enabled and configured for detailed HTTP request information on all Fortinet devices to support detection via the Sigma rules.</li>
<li>Monitor network traffic for unusual outbound connections originating from Fortinet devices, especially after patching, as a potential indicator of prior compromise (referencing <code>network_connection</code> log source).</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>data-exfiltration</category><category>vulnerability</category><category>fortinet</category><category>network-appliance</category></item></channel></rss>