Fortinet addresses critical path traversal vulnerability with CVSS score of 9.8

Published:

A critical path traversal vulnerability has been identified in Fortinet products, with a CVSS score of 9.8. This flaw allows unauthenticated attackers to write arbitrary files on the underlying system through specially crafted HTTP or HTTPS requests. The vulnerability has reportedly been exploited in the wild, prompting Fortinet to urge customers to implement the recommended workarounds immediately.

Middle East Relevance

This vulnerability may impact organizations in the UAE and the broader Middle East that utilize Fortinet products. While specific local incidents have not been reported, the widespread use of Fortinet solutions in the region necessitates vigilance among users to mitigate potential risks associated with this vulnerability.

Key Facts

  • CVE Identifier: Not specified in the source material.
  • CVSS Score: 9.8, indicating critical severity.
  • Vulnerability Type: Path Traversal (CWE-22) and NULL Byte Injection (CWE-158).
  • Exploitation Status: Reported to be actively exploited in the wild.
  • Recommended Action: Customers are urged to apply the provided workarounds.

Technical Context

The vulnerability arises from improper limitations on pathnames, allowing attackers to traverse directories and potentially write files to unauthorized locations on the system. This flaw can be exploited via crafted HTTP or HTTPS requests, making it critical for organizations to assess their exposure and implement necessary mitigations. The specific versions affected and detailed remediation steps were not provided in the source material.

Risk and Decision

Organizations using Fortinet products should prioritize addressing this vulnerability due to its high CVSS score and confirmed exploitation in the wild. IT security teams must assess their systems for potential exposure and implement the recommended workarounds to prevent unauthorized access and data manipulation. Failure to act could lead to significant operational and reputational risks.

Defensive Guidance

Fortinet has advised customers to apply the specified workarounds to mitigate the risk associated with this vulnerability. Organizations should verify their systems against the vulnerability and monitor for any unusual activity that may indicate exploitation attempts.

Source and Evidence

This report is based on information from Fortinet’s PSIRT advisory, which outlines the critical path traversal vulnerability and its implications. The advisory was last revised on October 1, 2026. For further details, refer to the original advisory at Fortinet.

CWME will continue tracking regional implications as more verified information becomes available.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Hiperdist appointed as authorized Huawei Cloud distributor to enhance UAE channel ecosystem

Hiperdist has been appointed as an authorized distributor for Huawei Cloud in the UAE, marking a significant expansion of their partnership aimed at enhancing...

Vicksburg, Mississippi, shuts down city systems following ransomware attack

A ransomware attack has led to the shutdown of computer systems in Vicksburg, Mississippi, as confirmed by Mayor Willis Thompson on Thursday. The incident,...

CrowdStrike details ClickFix attacks and strategies to mitigate user-executed threats

ClickFix attacks represent a sophisticated social engineering technique that exploits user behavior to execute malicious commands on their systems. Observed by CrowdStrike Intelligence, these...

Police arrest 16-year-old suspected of running KillSec ransomware group in Spain

Spanish authorities have arrested a 16-year-old suspected of leading the KillSec ransomware group, which is accused of stealing sensitive data from various organizations and...