Italian and Colombian cyber authorities issued alerts on vulnerabilities affecting Fortinet products, with CSIRT Italia detailing multiple information-disclosure flaws in FortiSandbox and FortiAuthenticator and warning that two of the issues are rated high severity. The disclosed weaknesses could allow a malicious user to access sensitive information on affected systems, expanding risk for organizations that rely on these appliances for authentication and sandboxing functions.
CSIRT Italia said the affected products span specific version ranges and urged administrators to apply the updates referenced in Fortinet security bulletins. Separate COLCERT alerts also warned of critical vulnerabilities in Fortinet products, reinforcing the need for immediate review of exposed deployments even though the Colombian notices provided limited technical detail on affected versions, CVE identifiers, or exploitation activity.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
COLCERT issued alert "COLCERT AL – 20251217 - 089" warning of critical vulnerabilities detected in Fortinet products. The provided content does not identify specific products, CVEs, impact details, or remediation steps.
ACN/CSIRT Italia reported multiple information disclosure vulnerabilities affecting FortiSandbox and FortiAuthenticator, including two rated high severity. The notice says successful exploitation could expose sensitive information and recommends updating affected versions according to Fortinet security bulletins.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecolcert.gov.co
Open sourcecolcert.gov.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.