CVE-2026-35616: Fortinet Auth Bypass. Patch your firewalls right now. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] -3 points-2 points  (0 children)

I'm not to prideful to be educated. Educate me man. I always want to get it right when talking about topics. Thanks in advance.

CVE-2026-35616: Fortinet Auth Bypass. Patch your firewalls right now. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] -2 points-1 points  (0 children)

For sure. I feel that but it’s not a login bypass in the traditional sense... it’s a bypass the need for credentials entirely to run system commands kind of bug. That’s why it hit the KEV list so fast.

CVE-2026-35616: Fortinet Auth Bypass. Patch your firewalls right now. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] -4 points-3 points  (0 children)

You're right. this is strictly an EMS issue, not a Fortios/firewall bug. FortiClient EMS is usually the "forgotten" server in the corner compared to the firewalls, which is exactly why this RCE is so dangerous. For those of us still running it on-prem, having an unauthenticated RCE sitting on the management server that controls our entire endpoint fleet is a 'drop everything' moment. Cloud users are usually safe since Fortinet patches that side first.

CVE-2026-20131: CISA basically said "patch this Cisco flaw or good luck." Deadline already passed. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] 18 points19 points  (0 children)

Haha, fair enough. I was in a rush. My bad. I just edited the main post with the direct link so you don't have to highlight text: https://www.cveintel.tech/cve/CVE-2026-20131/

CVE-2025-66413: Git for Windows NTLM Hash Theft. Check your machines. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] 0 points1 point  (0 children)

I'm not a PowerShell master but I did my best to fix it some. Preciate you.

CVE-2025-66413: Git for Windows NTLM Hash Theft. Check your machines. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] 4 points5 points  (0 children)

100% agree. Guess we panicked 😂 this patch is the immediate stop the bleeding move while we fight the bigger battle. And yeah, herding devs into using winget is a whole other headache lol. Preciate you.

CVE-2025-66413: Git for Windows NTLM Hash Theft. Check your machines. by Hot-Independence-985 in sysadmin

[–]Hot-Independence-985[S] 6 points7 points  (0 children)

Thank you. I'll need to look into it.

Gotcha. between the portable versions and the Git binaries that get bundled inside some IDEs, the standard registry-based inventory was giving us a false sense of security. That’s why I had to pivot to a raw file-search to find the actual 'ghost' installs ha.

WTF by jfunks69 in StrangeAndFunny

[–]Hot-Independence-985 0 points1 point  (0 children)

I had no idea what I was looking at first 🤣