Cisco Secure Firewall ASA / FTD Remote Access SSL VPN | Cisco Secure Firewall ASA/FTD Remote Access SSL VPN DoS update Cisco disclosed an actively exploited Remote Access SSL VPN flaw that could let an unauthenticated attacker force an affected Secure Firewall ASA or FTD device to reload, with exact fixed ASA releases and FTD hotfix targets across current branches. | ASA 9.16.4.50 / 9.18.4.50 / 9.20.4.235 / 9.22.3.191 / 9.23.1.211 / 9.24.1.221 FTD 7.0.9.1-1 GC FTD 7.2.11.1-2 HM FTD 7.4.7.1-1 HK FTD 7.6.4.1-2 DD FTD 7.7.11.1-2 AN | 2026-08-11 | Official source ↗ |
Fortinet FortiOS Agentless VPN / FSSO | FG-IR-25-1052 LDAP authentication bypass in Agentless VPN and FSSO Fortinet disclosed an authentication-bypass flaw in FortiOS fnbamd that may let an unauthenticated attacker bypass LDAP authentication for Agentless VPN or FSSO policies under a specific LDAP-server configuration, with one active affected branch, a fixed release, and a practical workaround. | FortiOS 7.6.5+ | 2026-07-04 | Official source ↗ |
Zyxel ZLD firewalls | Zyxel fixes CVE-2026-14818 in ZLD firewalls Zyxel published a ZLD firewall advisory for a path traversal flaw in the configuration-file execution CLI command that could let an authenticated administrator execute a crafted malicious configuration file, with one clean patched target version across ATP and USG FLEX families. | ATP ZLD V5.43 USG FLEX ZLD V5.43 USG FLEX 50(W) / USG20(W)-VPN ZLD V5.43 | 2026-08-04 | Official source ↗ |
Fortinet FortiOS CAPWAP daemon | FG-IR-26-123 FortiOS CAPWAP daemon out-of-bounds write update Fortinet disclosed a high-severity CAPWAP daemon out-of-bounds write that may let an attacker controlling an authenticated FortiAP, FortiExtender, or FortiSwitch gain execution privileges on a FortiGate device, with clear fixed releases and a published workaround. | FortiOS 7.6.4+ FortiOS 7.4.9+ FortiOS 7.2.12+ | 2026-05-12 | Official source ↗ |
Cisco Secure Firewall ASA / FTD | Cisco Secure Firewall ASA/FTD persistence response after CISA ED 25-03 update Cisco told operators on affected Secure Firewall ASA and FTD hardware to check for compromise, reimage if needed, and move to listed fixed releases after disclosing a persistence mechanism that can survive earlier September 2025 fixes. | ASA 9.16.4.92 / 9.18.4.135 / 9.20.4.30 / 9.22.3.5 / 9.23.1.195 / 9.24.1.155 FTD 7.0.9 + FZ-7.0.9.1-3 FTD 7.2.11 + HI-7.2.11.1-1 FTD 7.4.7 FTD 7.6.4 + CC-7.6.4.1-1 FTD 7.7.11 + AE-7.7.11.1-4 | 2026-04-23 | Official source ↗ |
Zyxel USG FLEX H / uOS | Zyxel USG FLEX H privilege escalation security update Zyxel published a USG FLEX H firewall advisory covering incorrect permission assignment and improper privilege management issues that could let a local attacker escalate privileges; the vendor says patched uOS builds are available. | uOS V1.32 | 2025-04-22 | Official source ↗ |
Fortinet FortiOS administrative interface | FG-IR-24-535 authentication bypass using alternate path/channel Fortinet disclosed an authentication bypass that could allow a remote attacker to gain super-admin privileges via crafted requests to the Node.js websocket module or crafted CSF proxy requests; the vendor said it was being exploited in the wild. | FortiOS 7.0.17+ | 2025-03-31 | Official source ↗ |