描述:
Fortinet 发布了安全公告,以应对 Fortinet 系统的多个漏洞。攻击者可以向受影响的系统传送特制的请求,从而发动攻击。
有报告指一个服务被拒绝漏洞 (CVE-2026-49975,统称为「HTTP/2 Bomb」) 的概念验证 (PoC) 程式码已被公开,亦正处于被攻击的高风险。系统管理员应立即为受影响的系统安装修补程式,以减低受到网络攻击的风险。
受影响的系统:
- FortiOS 版本 7.2 (所有版本)、版本 7.4 (所有版本)、版本 7.6.1 至 7.6.6
- FortiWeb 版本 7.2 (所有版本)、版本 7.4 (所有版本)、版本 7.6.0 至 7.6.6、版本 8.0.0 至 8.0.2
- FortiManager 版本 7.2.5 至 7.2.9、版本 7.4.3 至 7.4.5、版本 7.6.1
- FortiManager Cloud 版本 7.2.5 至 7.2.9、版本 7.4.3 至 7.4.5、版本 7.6.1
- FortiClientWindows 版本 7.2.0 至 7.2.11、版本 7.4.0 至 7.4.3
- FortiProxy 版本 7.2 (所有版本)、版本 7.4.0 至 7.4.14、版本 7.6.0 至 7.6.6
- FortiPAM 版本 1.0 (所有版本)、版本 1.1 (所有版本)、版本 1.2 (所有版本)、版本 1.3 (所有版本)、版本 1.4 (所有版本)、版本 1.5 (所有版本)、版本 1.6 (所有版本)、版本 1.7 (所有版本)、版本 1.8 (所有版本)、版本 1.9.0 至 1.9.1
- FortiSwitchManager 版本 7.2.0 至 7.2.9
- FortiSIEM 版本 6.5 (所有版本)、版本 6.6 (所有版本)、版本 6.7 (所有版本)、版本 7.0 (所有版本)、版本 7.1 (所有版本)、版本 7.2 (所有版本)、版本 7.3.0 至 7.3.5、版本 7.4.0 至 7.4.2、版本 7.5.0
有关受影响产品的详细资料、请参阅供应商网站的相应安全公告中有关 “Affected Products” 的部分。
影响:
成功利用漏洞可以导致受影响的系统发生远端执行程式码、服务被拒绝、权限提升、绕过保安限制或仿冒诈骗。
建议:
现已有适用于受影响系统的修补程式。受影响系统的系统管理员应遵从供应商的建议,立即採取行动以降低风险。
进一步资讯:
- https://fortiguard.fortinet.com/psirt/FG-IR-26-156
- https://fortiguard.fortinet.com/psirt/FG-IR-26-157
- https://fortiguard.fortinet.com/psirt/FG-IR-26-158
- https://fortiguard.fortinet.com/psirt/FG-IR-26-159
- https://fortiguard.fortinet.com/psirt/FG-IR-26-160
- https://fortiguard.fortinet.com/psirt/FG-IR-26-161
- https://fortiguard.fortinet.com/psirt/FG-IR-26-162
- https://fortiguard.fortinet.com/psirt/FG-IR-26-163
- https://www.hkcert.org/tc/security-bulletin/fortinet-products-multiple-vulnerabilities_20260813
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26035
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-49975
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-70465 (to CVE-2026-70468)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-71407 (to CVE-2026-71408)