The Threat Signal created by the FortiGuard Labs is intended to provide you with insight on emerging issues that are trending within the cyber threat landscape. The Threat Signal will provide concise technical details about the issue, mitigation recommendations and a perspective from the FortiGuard Labs team in an FAQ style format.
|
What is the Vulnerability? |
FortiGuard Labs is tracking an exploitation risk associated with CVE-2026-42533, a heap-based buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus. The flaw occurs when the map directive uses regex matching and capture variables in a specific configuration pattern. An unauthenticated remote attacker can send crafted HTTP requests that may crash the NGINX worker process, resulting in denial of service, and potentially achieve remote code execution when ASLR is disabled or bypassed.
Fortinet has conducted an internal security review of products and services that use NGINX. Based on the current assessment, Fortinet products are not affected by CVE-2026-42533. |
|
What is the Recommended Mitigation? |
Affected products:
|
|
What FortiGuard Coverage is available? |
• FortiGuard IPS Service: Detects and blocks network-based attacks targeting vulnerable NGINX assets.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Attack? |
Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.
|
|
What is the recommended Mitigation? |
• Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs.
|
|
What FortiGuard Coverage is available? |
• FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets.
OT App Detection | FortiGuard Labs
|
|
What is the Attack? |
FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed.
|
|
What is the recommended Mitigation? |
Affected Versions:
|
|
What FortiGuard Coverage is available? |
|
|
What is the Attack? |
A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks. The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected organizations. |
|
What is the recommended Mitigation? |
Organizations using PTC Windchill or FlexPLM should:
|
|
What FortiGuard Coverage is available? |
• FortiGuard IPS Service helps detect and block exploitation attempts targeting vulnerable PTC Windchill PDMlink and FlexPLM servers before attackers can gain remote code execution.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Vulnerability? |
FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.
|
|
What is the recommended Mitigation? |
• Upgrade SP Page Builder to version 6.6.2 or later.
|
|
What FortiGuard Coverage is available? |
• FortiGuard Intrusion Prevention System (IPS) protects against exploitation attempts targeting vulnerable SP Page Builder deployments.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Vulnerability? |
Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands.
|
|
What is the recommended Mitigation? |
Organizations should:
|
|
What FortiGuard Coverage is available? |
• FortiGuard Intrusion Prevention System (IPS) protects against exploit attempts.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Vulnerability? |
FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code.
|
|
What is the recommended Mitigation? |
Affected:
|
|
What FortiGuard Coverage is available? |
• FortiGuard IPS protects against exploit attempts targeting vulnerable Ivanti Sentry appliances.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Attack? |
A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server.
|
|
What is the recommended Mitigation? |
Affected:
|
|
What FortiGuard Coverage is available? |
• FortiGuard IPS provides protection against exploit attempts targeting vulnerable services.
|
|
What is the Attack? |
Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign primarily targeted higher education institutions, with approximately 68% of identified victims belonging to the education sector.
|
|
What is the recommended Mitigation? |
Potentially exposed systems include:
|
|
What FortiGuard Coverage is available? |
• FortiGuard IPS: Detects and blocks exploitation attempts targeting Oracle PeopleSoft vulnerabilities.
Intrusion Prevention | FortiGuard Labs
|
|
What is the Vulnerability? |
Cisco has disclosed a critical security vulnerability, CVE-2026-20245, affecting Cisco Catalyst SD-WAN Manager and confirmed that it is being actively exploited in the wild. The vulnerability resides in the platform's command-line interface (CLI) and allows an authenticated attacker with netadmin privileges to execute arbitrary commands as root on the underlying operating system.
|
|
What is the recommended Mitigation? |
• Restrict access to SD-WAN Manager administrative interfaces to trusted management networks.
|
|
What FortiGuard Coverage is available? |
• FortiGuard Antivirus & Behavior Detection: Detects and blocks malicious payloads and abnormal process execution that may result from successful exploitation.
|