CVE Tools

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

SecurityWeekBy Ionut Arghire

PatchFortiOSFortiProxy

Our summary

Fortinet, Ivanti, and ServiceNow have issued patches for a total of 15 vulnerabilities affecting their products. Among them is a critical remote code execution flaw in ServiceNow's AI platform (CVE-2026-6875), which could be exploited without authentication. Ivanti addressed two issues in its Xtraction tool (CVE-2026-14902 and CVE-2026-14903), involving open redirect and path traversal risks. Fortinet published 11 advisories covering multiple products like FortiOS and FortiSandbox, fixing high-severity bugs that could lead to information disclosure and unauthorized access. None of the companies reported active exploitation of these flaws.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store