CRITICALVulnerability
Verified
Global

Critical Fortinet FortiManager Flaw Enables Managed Firewall Takeover

·Source: Fortinet PSIRT / Mandiant

Updated:

Executive Summary

CVE-2026-48788 allows registration of rogue FortiGate devices to FortiManager, enabling config push to entire managed firewall estate.

Analysis

Unauthenticated attackers can register rogue FortiGate devices and push malicious configs to all managed firewalls. CVSS 9.8. Mandiant links exploitation to UNC3886 deploying firmware implants surviving factory resets. Patch immediately and audit device registrations.

Timeline

Discovered
Mar 10, 2026
Exploitation Detected
Mar 12, 2026
Published
Mar 21, 2026
Patch Available
Mar 21, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-48788
Source Attribution

Originally published by Fortinet PSIRT / Mandiant on Mar 21, 2026. Verified by: CISA, Fortinet PSIRT, Mandiant.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-103264 — Fleet versions before 4.87.0 contain an authentication bypass vulnerability in t...

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migr

CVE-2026-103264
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-103255 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security

CVE-2026-103255
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-103248 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.

CVE-2026-103248
NIST NVD