Ivanti, Fortinet, and SAP have released security patches addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.
Fortinet fixed a command injection vulnerability (CVE-2026-25089, CVSS 9.1) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, allowing unauthenticated attackers to execute commands via crafted HTTP requests.
Ivanti addressed two critical flaws in Ivanti Sentry: CVE-2026-10520 (CVSS 10.0) is an OS command injection enabling remote unauthenticated root-level code execution, and CVE-2026-10523 (CVSS 9.9) is an authentication bypass allowing full administrative access. watchTowr Labs and Rapid7 provided technical details. CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog after reports of exploitation attempts against honeypots.
SAP released fixes for four critical vulnerabilities: CVE-2026-44748 (CVSS 9.9) XML signature wrapping in NetWeaver AS ABAP; CVE-2026-27671 (CVSS 9.8) memory corruption in NetWeaver and ABAP Platform; CVE-2026-22732 (CVSS 9.1) Spring security flaw in Commerce Cloud and Data Hub; and CVE-2026-40128 (CVSS 9.0) directory traversal in NetWeaver Application Server Java. Onapsis provided analysis on CVE-2026-44748.
No evidence of active exploitation in the wild was initially found, but Shadowserver Foundation observed exploitation attempts for CVE-2026-10520. Organizations are urged to apply patches promptly.
CVEs: CVE-2026-25089, CVE-2026-10520, CVE-2026-10523, CVE-2026-44748, CVE-2026-27671, CVE-2026-22732, CVE-2026-40128, CVE-2026-11645
Companies: Fortinet, Ivanti, SAP, watchTowr Labs, Rapid7, Onapsis, Shadowserver Foundation, CISA
Products: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, Ivanti Sentry, SAP NetWeaver AS ABAP, SAP ABAP Platform, SAP Commerce Cloud, SAP Data Hub
Original source: thehackernews.com