{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fortisiem--4.7.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":3.3,"id":"CVE-2024-47576"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FortiSIEM (\u003c 4.7.1)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","webserver","informational"],"_cs_type":"advisory","_cs_vendors":["Fortinet"],"content_html":"\u003cp\u003eFortinet has identified a vulnerability in FortiSIEM that exposes users to an open redirect attack. A remote, unauthenticated attacker can exploit this flaw to manipulate URL parameters, causing the application to redirect authenticated or unauthenticated users to a site of the attacker's choosing. This type of vulnerability is frequently leveraged in phishing campaigns, where attackers use trusted domain names to lend credibility to malicious links, increasing the likelihood that users will navigate to credential harvesting or malware delivery sites. Defenders should prioritize auditing web traffic logs for suspicious redirect patterns originating from their FortiSIEM infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to conduct more convincing social engineering and phishing attacks by leveraging the reputation of a legitimate organization's infrastructure. While this vulnerability does not provide direct access to the underlying server, it facilitates the compromise of end-user credentials and increases the success rate of subsequent endpoint exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize applying the vendor-supplied security patch to the affected FortiSIEM installation as specified in the official Fortinet security advisory. Monitor web access logs for anomalous redirect targets, specifically identifying URLs that navigate outside of the organization's sanctioned domain space.\u003c/p\u003e\n","date_modified":"2026-09-09T12:50:09Z","date_published":"2026-09-09T12:50:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fortinet-fortisiem-open-redirect/","summary":"A vulnerability in Fortinet FortiSIEM allows a remote, unauthenticated attacker to perform an open redirect, enabling the redirection of users to malicious or untrusted websites.","title":"Fortinet FortiSIEM Open Redirect Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-fortinet-fortisiem-open-redirect/"}],"language":"en","title":"CraftedSignal Threat Feed - FortiSIEM (\u003c 4.7.1)","version":"https://jsonfeed.org/version/1.1"}