{"id":1256,"date":"2026-06-10T16:08:35","date_gmt":"2026-06-10T16:08:35","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1256"},"modified":"2026-06-10T16:08:35","modified_gmt":"2026-06-10T16:08:35","slug":"ivanti-fortinet-and-sap-release-patches-for-multiple-critical-vulnerabilities","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1256","title":{"rendered":"Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 10, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Patch Management<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhs2l0GUUy91D4hHU067eYWpRzvSJGcfOkHce2jcVXZGWI9sld0hgaomhoKTc3dYEXEbz05oZQ5mFzo34eXp-wNJ2j_ofUjXjR7ZR5obszwH7bCRRmah9Q9HY3RSDrwrAf8QD162ca7nvxTRELWzcVW8AbbVMpXJfHXtaYEiSxXAw49VpCG8ep33SbGeLSF\/s1700-e365\/ivanti.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure.<\/p>\n<p>The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It&#8217;s tracked as <b>CVE-2026-25089<\/b> (CVSS score: 9.1).<\/p>\n<p>\u00abAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests,\u00bb Fortinet <a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-26-141\">said<\/a>.<\/p>\n<p>The issue impacts the following products and versions &#8211;<\/p>\n<ul>\n<li>FortiSandbox 5.0.0 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<li>FortiSandbox 4.4.0 through 4.4.8 (Upgrade to 4.4.9 or above)<\/li>\n<li>FortiSandbox Cloud 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<li>FortiSandbox PaaS 5.0.4 through 5.0.5 (Upgrade to 5.0.6 or above)<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>On Tuesday, Ivanti also <a href=\"https:\/\/hub.ivanti.com\/s\/article\/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US\">published<\/a> fixes for two critical security flaws impacting Ivanti Sentry (formerly MobileIron Sentry) &#8211;<\/p>\n<ul>\n<li><b>CVE-2026-10520<\/b> (CVSS score: 10.0) &#8211; An operating system command injection vulnerability before versions R10.5.2, R10.6.2, and R10.7.1 that allows a remote unauthenticated user to achieve root-level remote code execution.<\/li>\n<li><b>CVE-2026-10523<\/b> (CVSS score: 9.9) &#8211; An authentication bypass vulnerability before versions R10.5.2, R10.6.2, and R10.7.1 that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.<\/li>\n<\/ul>\n<p>watchTowr Labs, which published additional details of CVE-2026-10520, said an attacker could exploit the vulnerability by issuing a specially crafted HTTP request to the \u00ab\/mics\/api\/v2\/sentry\/mics-config\/handleMessage\u00bb endpoint, which is then interpreted as a MICS configuration command and executed by a backend component named \u00abhandleExecute().\u00bb<\/p>\n<p>The patch shipped by Ivanti incorporates additional controls that block access to the vulnerable endpoint, causing unauthenticated requests to be redirected to the login page.<\/p>\n<p>\u00abIvanti did not just remove attacker control over the vulnerable execution path,\u00bb security researcher Sonny Macdonald <a href=\"https:\/\/labs.watchtowr.com\/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520\/\">said<\/a>. \u00abThey also added a layer of protection in front of it to make reaching the endpoint significantly more difficult. In other words: they added authentication.\u00bb<\/p>\n<p>Rounding off the list of updates is SAP, which <a href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/june-2026.html\">pushed out fixes<\/a> for four critical vulnerabilities in NetWeaver AS ABAP and ABAP Platform, as well as SAP Commerce Cloud and SAP Data Hub &#8211;<\/p>\n<ul>\n<li><b>CVE-2026-44748<\/b> (CVSS score: 9.9) &#8211; XML signature wrapping vulnerability in SAML authentication in SAP NetWeaver AS ABAP and ABAP Platform<\/li>\n<li><b>CVE-2026-27671<\/b> (CVSS score: 9.8) &#8211; Memory corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform<\/li>\n<li><b>CVE-2026-22732<\/b> (CVSS score: 9.1) &#8211; Potential Spring security vulnerability within SAP Commerce Cloud and SAP Data Hub<\/li>\n<li><b>CVE-2026-40128<\/b> (CVSS score: 9.0) &#8211; Directory traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe application allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents with tampered identity information to the verifier,\u00bb SAP security company Onapsis <a href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-june-2026\/\">said<\/a>.<\/p>\n<p>\u00abDue to an improper XML signature verification, the manipulated identity information is accepted, leading to unauthorized access to sensitive user data and potential disruption of normal system usage.\u00bb<\/p>\n<p>As for CVE-2026-27671, the defect allows an unauthenticated attacker to send a crafted RFC request that exploits how the SAP kernel validates the RFC protocol to achieve memory corruption.<\/p>\n<p>There is no evidence that any of the aforementioned flaws have been exploited in the wild. However, it&#8217;s always a safe practice to update to the latest version for optimal protection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 10, 2026Vulnerability \/ Patch Management Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1257,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[58,1075,543,1170,57,1588,1231,474],"class_list":["post-1256","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-critical","tag-fortinet","tag-ivanti","tag-multiple","tag-patches","tag-release","tag-sap","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1256","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1256"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1256\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1257"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}