Patch Parade: Fortinet and Ivanti Squash Bugs Before They Bite!

Fortinet and Ivanti release patches for over a dozen vulnerabilities, including high-severity flaws. Ivanti’s update tackles bugs that could leak credentials, while Fortinet addresses an OS command injection bug in FortiADC. Thankfully, no wild exploitation reported yet. For more details, check Fortinet’s PSIRT advisories page.

Pro Dashboard

Hot Take:

Fortinet and Ivanti just dropped a bombshell of vulnerability fixes, and it’s like watching a soap opera unfold in the cybersecurity world. The drama includes hardcoded keys, credential leaks, and even a plot twist with an OS command injection bug. Grab your popcorn, folks, because patching day has never been this riveting!

Key Points:

  • Ivanti addressed three high-severity bugs in Workspace Control, risking credential leaks.
  • Fortinet rolled out 14 patches for one high-severity and 13 medium-severity vulnerabilities.
  • The high-severity issue, CVE-2025-31104, involves OS command injection in FortiADC.
  • Fortinet’s vulnerabilities could lead to unauthorized access, SSRF attacks, and privilege escalation.
  • No known exploits in the wild for these vulnerabilities have been reported yet.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?