Why Should I Care? โ€” 2026-08-13 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 21 RADAR ยท โšช 233 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-08-13

24 vendor intel items scanned  |  ๐Ÿ”ด 0 HIGH  |  ๐ŸŸก 3 MEDIUM  |  ๐Ÿ”ต 21 RADAR  |  โšช 233 FILTERED

โœ… No critical items today.

Everything else can wait.

๐ŸŸก Medium โ€” review when time permits:

  1. Heap overflow in kernel driver due to missing size validation โ€” Yes, if you run FortiClient Windows: unauthenticated RCE via malicious DNS responses.
  2. FGFM Authentication Weakening via CLI Configuration โ€” Yes, if you run FortiManager or FortiManager Cloud with a specific CLI option set: unauthenticated attackers can impersonate any managed FortiGate device.
  3. Broken access control in the RADIUS type admin group โ€” Yes, if you run FortiWeb with Remote Radius Type Admin Authentication configured: unauthenticated access to GUI/CLI allows full control.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now

No HIGH priority items in the last 24h.


Why Should I Care? ๐ŸŸก MEDIUM (3)


Heap overflow in kernel driver due to missing size validation

Fortinet PSIRT | CVSS 7.3

โ“ Why Should I Care?
Yes, if you run FortiClient Windows: unauthenticated RCE via malicious DNS responses. Patch now.

๐ŸŽฏ Affected versions: FortiClient Windows versions prior to the patched version

๐ŸŽญ In plain English:
If you use FortiClient on a Windows machine, an attacker can send specially crafted DNS responses that exploit a flaw in the software, allowing them to run any code they want on your computer without needing your password. This means they could take full control of your system and do anything from stealing files to installing malware.

๐Ÿ”ง Prerequisites:

  • Attacker must be able to intercept or alter DNS traffic
  • FortiClient Windows version is vulnerable

โฑ Urgency: High urgency due to the potential for unauthenticated remote code execution, which could lead to full system compromise.

๐Ÿ’ก Context: The kernel driver in FortiClient does not properly validate the size of input data when processing DNS responses, leading to a heap overflow.


FGFM Authentication Weakening via CLI Configuration

Fortinet PSIRT | CVSS 7.3

โ“ Why Should I Care?
Yes, if you run FortiManager or FortiManager Cloud with a specific CLI option set: unauthenticated attackers can impersonate any managed FortiGate device. Patch immediately.

๐ŸŽฏ Affected versions: FortiManager and FortiManager Cloud with the specific CLI option set

๐ŸŽญ In plain English:
An attacker can pretend to be any of your managed FortiGate devices by sending special requests, if they have a valid certificate. This means they could potentially take control of your network configurations without needing to know any passwords.

๐Ÿ”ง Prerequisites:

  • Specific CLI option set
  • Valid certificate

โฑ Urgency: High urgency due to the potential for unauthenticated impersonation and unauthorized access to managed devices.


Broken access control in the RADIUS type admin group

Fortinet PSIRT | CVSS 8.8

โ“ Why Should I Care?
Yes, if you run FortiWeb with Remote Radius Type Admin Authentication configured: unauthenticated access to GUI/CLI allows full control. Patch immediately.

๐ŸŽฏ Affected versions: FortiWeb versions with Remote Radius Type Admin Authentication enabled
Not affected: All FortiWeb versions without Remote Radius Type Admin Authentication configured

๐ŸŽญ In plain English:
An attacker can log into your firewall's admin interface using any username and password, gaining full control over the device. They could change settings, monitor traffic, or even shut down security features.

๐Ÿ”ง Prerequisites:

  • Remote Radius Type Admin Authentication must be enabled

โฑ Urgency: High urgency due to potential for unauthenticated access allowing complete takeover of the device.


Why Should I Care? ๐Ÿ”ต On the Radar (21)


โšช 233 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 9 vendor feeds  |  CISA KEV

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23 35 vendor intel items scanned ย |ย  ๐Ÿ”ด 5 HIGH ย |ย  ๐ŸŸก 3 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic