Patch Parade: Fortinet and Ivanti Squash Bugs Before They Bite!
Fortinet and Ivanti release patches for over a dozen vulnerabilities, including high-severity flaws. Ivanti’s update tackles bugs that could leak credentials, while Fortinet addresses an OS command injection bug in FortiADC. Thankfully, no wild exploitation reported yet. For more details, check Fortinet’s PSIRT advisories page.

Hot Take:
Fortinet and Ivanti just dropped a bombshell of vulnerability fixes, and it’s like watching a soap opera unfold in the cybersecurity world. The drama includes hardcoded keys, credential leaks, and even a plot twist with an OS command injection bug. Grab your popcorn, folks, because patching day has never been this riveting!
Key Points:
- Ivanti addressed three high-severity bugs in Workspace Control, risking credential leaks.
- Fortinet rolled out 14 patches for one high-severity and 13 medium-severity vulnerabilities.
- The high-severity issue, CVE-2025-31104, involves OS command injection in FortiADC.
- Fortinet’s vulnerabilities could lead to unauthorized access, SSRF attacks, and privilege escalation.
- No known exploits in the wild for these vulnerabilities have been reported yet.
Already a member? Log in here