Close Menu
    What's Hot

    After Global Order Will Come an Era of Global Ordering

    Opinion | Cultivating a New Generation of Readers and a Love of Books

    ActBlue C.E.O. Invokes Fifth Amendment Repeatedly in Testimony to Congress

    Facebook X (Twitter) Instagram
    Trending
    • After Global Order Will Come an Era of Global Ordering
    • Opinion | Cultivating a New Generation of Readers and a Love of Books
    • ActBlue C.E.O. Invokes Fifth Amendment Repeatedly in Testimony to Congress
    • The Geopolitics of the World Cup
    • Souleymane Diallo Dies at 80; Daring, Mocking Journalist in Guinea
    • Bill Gates goes to Capitol Hill in Epstein case as his ventures feel the effects – GeekWire
    • Zest launches a restaurant discovery app powered by where people actually eat
    • Skyward Specialty: A Good Combination Of Value And Growth Following Its De-Rating (SKWD)
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

    adminBy adminJune 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 10, 2026Vulnerability / Patch Management

    Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

    Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure.

    The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It’s tracked as CVE-2026-25089 (CVSS score: 9.1).

    “An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests,” Fortinet said.

    The issue impacts the following products and versions –

    • FortiSandbox 5.0.0 through 5.0.5 (Upgrade to 5.0.6 or above)
    • FortiSandbox 4.4.0 through 4.4.8 (Upgrade to 4.4.9 or above)
    • FortiSandbox Cloud 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)
    • FortiSandbox PaaS 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)
    Cybersecurity

    On Tuesday, Ivanti also published fixes for two critical security flaws impacting Ivanti Sentry (formerly MobileIron Sentry) –

    • CVE-2026-10520 (CVSS score: 10.0) – An operating system command injection vulnerability before versions R10.5.2, R10.6.2, and R10.7.1 that allows a remote unauthenticated user to achieve root-level remote code execution.
    • CVE-2026-10523 (CVSS score: 9.9) – An authentication bypass vulnerability before versions R10.5.2, R10.6.2, and R10.7.1 that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.

    watchTowr Labs, which published additional details of CVE-2026-10520, said an attacker could exploit the vulnerability by issuing a specially crafted HTTP request to the “/mics/api/v2/sentry/mics-config/handleMessage” endpoint, which is then interpreted as a MICS configuration command and executed by a backend component named “handleExecute().”

    The patch shipped by Ivanti incorporates additional controls that block access to the vulnerable endpoint, causing unauthenticated requests to be redirected to the login page.

    “Ivanti did not just remove attacker control over the vulnerable execution path,” security researcher Sonny Macdonald said. “They also added a layer of protection in front of it to make reaching the endpoint significantly more difficult. In other words: they added authentication.”

    Rounding off the list of updates is SAP, which pushed out fixes for four critical vulnerabilities in NetWeaver AS ABAP and ABAP Platform, as well as SAP Commerce Cloud and SAP Data Hub –

    • CVE-2026-44748 (CVSS score: 9.9) – XML signature wrapping vulnerability in SAML authentication in SAP NetWeaver AS ABAP and ABAP Platform
    • CVE-2026-27671 (CVSS score: 9.8) – Memory corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
    • CVE-2026-22732 (CVSS score: 9.1) – Potential Spring security vulnerability within SAP Commerce Cloud and SAP Data Hub
    • CVE-2026-40128 (CVSS score: 9.0) – Directory traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
    Cybersecurity

    “The application allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents with tampered identity information to the verifier,” SAP security company Onapsis said.

    “Due to an improper XML signature verification, the manipulated identity information is accepted, leading to unauthorized access to sensitive user data and potential disruption of normal system usage.”

    As for CVE-2026-27671, the defect allows an unauthenticated attacker to send a crafted RFC request that exploits how the SAP kernel validates the RFC protocol to achieve memory corruption.

    There is no evidence that any of the aforementioned flaws have been exploited in the wild. However, it’s always a safe practice to update to the latest version for optimal protection.

    critical Fortinet Ivanti Multiple Patches release SAP Vulnerabilities
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleDirectors in Hollywood close in on a 4-year deal with studios and streaming services
    Next Article How memory tools can make AI models worse
    admin
    • Website

    Related Posts

    Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security

    June 10, 2026

    Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

    June 10, 2026

    At Least 12 Dead After Shooting by Multiple Attackers in Johannesburg

    June 10, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    After Global Order Will Come an Era of Global Ordering

    Opinion | Cultivating a New Generation of Readers and a Love of Books

    ActBlue C.E.O. Invokes Fifth Amendment Repeatedly in Testimony to Congress

    The Geopolitics of the World Cup

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by