This is a compilation of four vulnerability advisories issued by the Canadian Centre for Cyber Security on 2026-07-27, covering Microsoft Edge (Chromium-based), Redis, multiple Fortinet products, and Erlang/OTP. The most significant item is an update to a prior Fortinet advisory (AV26-109) noting that CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities database, confirming active exploitation of a vulnerability spanning FortiAuthenticator, FortiClientWindows, FortiOS, and FortiSandbox. No technical exploitation details, IOCs, or attack narratives are provided in the advisories; they primarily direct readers to vendor patch/update resources.
Fortinet
13 posts
Cyber Centre Daily Advisory Digest — 2026-07-27 (4 advisories) Cyber Centre Daily Advisory Digest — 2026-07-16 (7 advisories) The Canadian Centre for Cyber Security published 7 security advisories on July 16, 2026, covering Zoom, Splunk, JetBrains, Grafana, Microsoft, and Fortinet products. The most critical items are three Microsoft CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644) and three Fortinet FortiSandbox CVEs (CVE-2026-25089, CVE-2026-39813, CVE-2026-39808) that have been confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities database. Splunk Enterprise also has critical vulnerabilities including a CSRF-based SPL command bypass and a path traversal in the App Install REST endpoint.
22nd June – Threat Intelligence Report This threat intelligence report highlights recent data breaches involving third-party vendors, emerging AI threat vectors such as prompt injection and WebSocket abuse, and active exploitation of critical vulnerabilities in Fortinet, Cisco, and Splunk products. Additionally, seasonal phishing campaigns targeting travelers and Amazon Prime members are surging alongside a cross-platform Rust-based crypto clipboard hijacker.
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways The NCSC has issued an alert regarding a global campaign targeting Fortinet firewalls and VPN gateways using brute-force and credential stuffing techniques. A threat actor has leaked a database of compromised credentials, prompting organizations to urgently check for exposure, investigate for unauthorized access or persistence, and perform factory resets on compromised devices.
Cyber Centre Daily Advisory Digest — 2026-06-18 (1 advisories) The Canadian Centre for Cyber Security issued an alert regarding 'FortiBleed,' a widespread campaign involving the leak of thousands of compromised credentials for Fortinet firewalls and VPN gateways. Threat actors can leverage these credentials, alongside vulnerabilities like CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719, to gain remote access, create unauthorized accounts, and modify critical security controls.
Cyber Centre Daily Advisory Digest — 2026-06-16 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical vulnerabilities across Cisco, Fortinet, and Zyxel products. Notably, CVE-2026-20262 in Cisco Catalyst SD-WAN Manager and multiple Fortinet CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively being exploited in the wild, prompting immediate patching requirements.
AL25-019 - Vulnerabilities impacting Fortinet products - FortiCloud SSO Login Authentication Bypass - CVE-2025-59718 and CVE-2025-59719 - Update 2 Critical vulnerabilities in Fortinet products allow unauthenticated attackers to bypass FortiCloud SSO and SAML login authentication using crafted SAML response messages. Active exploitation has been observed in the wild, necessitating immediate patching or the disabling of the FortiCloud SSO feature and restriction of internet-facing administrative access.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.
Thus Spoke…The Gentlemen A recent leak of internal communications and backend data from 'The Gentlemen' RaaS operation has revealed the group's highly structured operational model and mature toolset. The threat actors actively exploit edge appliances and NTLM relay vulnerabilities for initial access, followed by extensive use of red-team tools and custom EDR evasion techniques to deploy their cross-platform ransomware.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven actively exploited vulnerabilities affecting Microsoft, Adobe, and Fortinet products to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations to reduce exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-04-07 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding a critical API authentication and authorization bypass vulnerability (CVE-2026-35616) in Fortinet FortiClientEMS. Affecting versions 7.4.5 to 7.4.6, this flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation and requiring immediate patching.
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-35616, an improper access control vulnerability in Fortinet FortiClient EMS, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. All organizations are strongly urged to prioritize the timely remediation of this vulnerability to reduce their exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-03-30 (10 advisories) The Canadian Centre for Cyber Security released a daily digest of 10 security advisories highlighting critical vulnerabilities across multiple vendors. Notably, vulnerabilities in Fortinet FortiClientEMS (CVE-2026-21643) and Citrix NetScaler (CVE-2026-3055) are currently being exploited in the wild, requiring immediate patching and potential incident response actions if compromise is suspected.