Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Fortinet, Ivanti, and SAP issued fixes for critical flaws that could enable code execution, account takeover, or data exposure.
Intelligence analysis by GPT-5.4 Mini

Three major enterprise vendors shipped urgent security updates: Fortinet for a FortiSandbox command-injection issue, Ivanti for two critical Sentry bugs, and SAP for four critical flaws across NetWeaver and related products. The article says none of the vulnerabilities are known to be exploited in the wild.
Three big software makers found serious holes in their products and patched them. It is like fixing unlocked doors and broken locks before thieves try them, even though no break-in has been seen yet.
Analysis
Fortinet
Fortinet fixed a command-injection flaw in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web UI tracked as CVE-2026-25089 with a CVSS score of 9.1. The company says an unauthenticated attacker could send specially crafted HTTP requests to run unauthorized commands. Affected versions include FortiSandbox 5.0.0 through 5.0.5, 4.4.0 through 4.4.8, and the cloud/PaaS 5.0.4 through 5.0.5 lines.
Ivanti
Ivanti released fixes for two critical issues in Ivanti Sentry, formerly MobileIron Sentry. CVE-2026-10520 is a command-injection flaw before R10.5.2, R10.6.2, and R10.7.1 that can allow remote unauthenticated root-level code execution. CVE-2026-10523 is an authentication bypass before the same fixed versions, letting an attacker create arbitrary administrative accounts and gain full admin access. watchTowr Labs said the first flaw can be reached through a crafted request to the handleMessage endpoint, which is interpreted by a backend component. Ivanti also added controls that block direct access to the vulnerable path and redirect unauthenticated requests to the login page.
SAP
SAP patched four critical vulnerabilities spanning NetWeaver AS ABAP, ABAP Platform, SAP Commerce Cloud, SAP Data Hub, and NetWeaver AS Java. The list includes an XML signature wrapping flaw in SAML auth (CVE-2026-44748), a memory corruption issue in ABAP (CVE-2026-27671), a potential Spring security issue in Commerce Cloud and Data Hub (CVE-2026-22732), and a directory traversal flaw in the Java Web Container (CVE-2026-40128). Onapsis said the SAML issue could let manipulated identity data be accepted, creating unauthorized access to sensitive user data.
The article says there is no evidence these flaws have been exploited in the wild, but recommends updating to the latest versions for protection.
Key points
- Fortinet patched CVE-2026-25089, a critical FortiSandbox command-injection flaw that can be triggered with crafted HTTP requests.
- Ivanti fixed two critical Sentry vulnerabilities: one for root-level remote code execution and another for authentication bypass and admin account creation.
- SAP released fixes for four critical issues across NetWeaver, ABAP Platform, Commerce Cloud, Data Hub, and Java Web Container components.
- The article says there is no evidence of active exploitation in the wild.
- The main defensive advice is to update to the latest vendor releases as soon as possible.
If organizations install the updates quickly, they can close off attack paths that could lead to remote control, admin takeover, or sensitive data exposure. The vendor fixes also add extra blocking in at least one case, which may raise the bar for attackers even before upgrades are complete.
If patching is delayed, exposed systems could remain vulnerable to attacks that do not require an account, especially for the Fortinet and Ivanti issues. The SAP flaws also affect core enterprise platforms, so an unpatched deployment could expose authentication, data integrity, or server stability risks.



