Fortinet Identified Critical Security Vulnerabilities

Unauthenticated attackers have actively exploited path traversal and null byte flaws in Fortinet systems.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of a matte steel server chassis, representing enterprise network security infrastructure.
Fortinet has disclosed critical path traversal and null byte vulnerabilities in its software, noting that attackers are currently exploiting the flaws to write arbitrary files. AI Illustration. Upload story photo >

Live Poll

Is now the right time for your organization to accelerate its software patching schedule?

Fortinet has identified two distinct vulnerabilities in its software that allow unauthenticated attackers to write arbitrary files to a system. The company confirmed that these flaws are currently being exploited in the wild.

Why it matters

These vulnerabilities, categorized as path traversal and null byte flaws, represent a severe risk to network integrity by granting attackers unauthorized file-system access. Their active exploitation necessitates immediate action from administrators to secure affected infrastructure.

The flaws are identified as CWE-22, a path traversal vulnerability where software improperly limits a pathname to a restricted directory, and CWE-158, a null byte vulnerability involving improper neutralization of null characters. Both allow arbitrary file writing via crafted HTTP or HTTPS requests.

The players

Fortinet

A global cybersecurity company that develops and markets high-performance network security appliances and subscription-based threat intelligence services.

The details

Attackers leverage these vulnerabilities by sending specially crafted HTTP or HTTPS requests to the affected Fortinet systems. These requests bypass directory restrictions, allowing a remote, unauthenticated user to write arbitrary files on the target system. Because the system fails to correctly sanitize null bytes or path sequences, it interprets these malicious strings as legitimate instructions, resulting in unauthorized command or data injection at the file-system level.

Timeline

  1. October 1, 2026: Fortinet published the security advisory detailing the vulnerabilities.

The Tech Race

This incident mirrors the security challenges seen during the 2021 Kaseya VSA supply chain attack, highlighting the ongoing industry race to eliminate unauthenticated entry points in management software. Cybersecurity teams remain in a defensive cycle as exploit speed consistently tracks with the disclosure of such flaws.

System administrators must immediately review the provided guidance and apply recommended workarounds to mitigate unauthorized access risks. Security teams should prioritize patching or configuring their environments to neutralize incoming malicious HTTP and HTTPS requests.

The takeaway

The active exploitation of these flaws necessitates an immediate audit of all publicly facing network appliances. Administrators should monitor official vendor channels for additional patches and track the effectiveness of current workarounds against ongoing exploitation trends.

Further reading

For more on evolving threat vectors and defense strategies, visit Cybersecurity.

More information

Review the full Fortinet security advisory and workaround details to protect your infrastructure.

Source note: This article includes information reported by FortiGuard Labs.

Live Poll

Is now the right time for your organization to accelerate its software patching schedule?