CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

June 25, 2026

Ivanti, Fortinet, and SAP have released security patches addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.

Fortinet fixed a command injection vulnerability (CVE-2026-25089, CVSS 9.1) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI, allowing unauthenticated attackers to execute commands via crafted HTTP requests.

Ivanti addressed two critical flaws in Ivanti Sentry: CVE-2026-10520 (CVSS 10.0) is an OS command injection enabling remote unauthenticated root-level code execution, and CVE-2026-10523 (CVSS 9.9) is an authentication bypass allowing full administrative access. watchTowr Labs and Rapid7 provided technical details. CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog after reports of exploitation attempts against honeypots.

SAP released fixes for four critical vulnerabilities: CVE-2026-44748 (CVSS 9.9) XML signature wrapping in NetWeaver AS ABAP; CVE-2026-27671 (CVSS 9.8) memory corruption in NetWeaver and ABAP Platform; CVE-2026-22732 (CVSS 9.1) Spring security flaw in Commerce Cloud and Data Hub; and CVE-2026-40128 (CVSS 9.0) directory traversal in NetWeaver Application Server Java. Onapsis provided analysis on CVE-2026-44748.

No evidence of active exploitation in the wild was initially found, but Shadowserver Foundation observed exploitation attempts for CVE-2026-10520. Organizations are urged to apply patches promptly.

CVEs: CVE-2026-25089, CVE-2026-10520, CVE-2026-10523, CVE-2026-44748, CVE-2026-27671, CVE-2026-22732, CVE-2026-40128, CVE-2026-11645

Companies: Fortinet, Ivanti, SAP, watchTowr Labs, Rapid7, Onapsis, Shadowserver Foundation, CISA

Products: FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS, Ivanti Sentry, SAP NetWeaver AS ABAP, SAP ABAP Platform, SAP Commerce Cloud, SAP Data Hub