Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Fortinet PSIRT

Out of bounds read in GUI

An out-of-bounds read vulnerability (CVE-2025-53379, CVSSv3 7.0) in FortiAuthenticator's GUI allows an unauthenticated remote attacker to retrieve sensitive information via a specially crafted request. Affected versions are FortiAuthenticator 6.6.0 through 6.6.2 and 6.5.0 through 6.5.7. The solution is to upgrade to version 6.6.3 or above for the 6.6 branch, or to the upcoming 6.5.8 or above for the 6.5 branch.
Read Full Article →

PSIRT Out of bounds read in GUI Summary An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Version Affected Solution FortiAuthenticator 8.0 Not affected Not Applicable FortiAuthenticator 6.6 6.6.0 through 6.6.2 Upgrade to 6.6.3 or above FortiAuthenticator 6.5 6.5.0 through 6.5.7 Upgrade to upcoming 6.5.8 or above Acknowledgement Fortinet is pleased to thank Jonathan Bailey and Jon Kraft from BCI (Business Communications, Inc.) for reporting this vulnerability under responsible disclosure. Timeline 2026-07-14: Initial publication IR Number FG-IR-26-146 Published Date Jul 14, 2026 Component GUI Severity High Discovered External Attack Type Unauthenticated Known Exploited No CVSSv3 Score 7.0 Impact Information disclosure CVE ID CVE-2025-53379 Download CVRF CSAF

Share this article