Topic: sql injection vulnerability

  • Active Exploit Targets Fortinet FortiClient EMS Vulnerability

    Active Exploit Targets Fortinet FortiClient EMS Vulnerability

    A critical SQL injection vulnerability (CVE-2026-21643) in Fortinet's Endpoint Management Server is being actively exploited, allowing unauthenticated attackers to execute arbitrary code and take over systems. Fortinet released patches earlier this year in versions 7.2.4 and 8.0.2, and administra...

    Read More »
  • Patch Now: FortiWeb Pre-Auth RCE Exploits Released

    Patch Now: FortiWeb Pre-Auth RCE Exploits Released

    A critical vulnerability (CVE-2025-25257, 9.8/10 severity) in Fortinet's FortiWeb WAF allows unauthenticated remote code execution via SQL injection, requiring immediate patching. Exploits leverage improper SQL sanitization in the Fabric Connector, enabling attackers to inject malicious commands ...

    Read More »
  • Covert Surveillance App Exposes 62,000 User Passwords

    Covert Surveillance App Exposes 62,000 User Passwords

    A security flaw in the Android surveillance app Catwatchful exposed 62,000 users' sensitive data, including unencrypted passwords and email addresses. Catwatchful markets itself as undetectable and resistant to removal, raising concerns about misuse despite being framed as a parental control tool...

    Read More »