NCSC-2026-0240 [1.00] [M/H] Vulnerabilities fixed in multiple Fortinet products
Fortinet has fixed vulnerabilities in multiple versions of FortiSIEM (Windows Agent and general product versions), FortiOS, FortiPAM, and FortiProxy. A vulnerability in FortiSIEM Windows Agent (versions 7.4.0 to 7.4.1) identified as CVE-2026-59841 allows malicious actors on the same local network to escalate privileges when the 'Supers Override' feature is active. This enables attackers to execute arbitrary code and compromise the integrity of the agent. The other vulnerabilities can be exploited by an authenticated attacker with elevated privileges remotely, or with physical access. See attached references for more information.
CSIRTS triage
- What
- A vulnerability allows local network attackers to escalate privileges and execute arbitrary code.
- Who is affected
- Deployments of FortiSIEM Windows Agent versions 7.4.0 to 7.4.1.
- Urgency
- Remediation is urgent due to the potential for local privilege escalation and code execution.
- Action
- Update to the latest version of FortiSIEM.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiSIEM
Get an email when a new FortiSIEM advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0240
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598410.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59841 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Fortinet FortiSIEM: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis
- highCVE-2026-59841: A improper restriction of communication channel to intended endpoints vulnerability in Fortine…nvd
- unknownSupers override fails to properly override supervisor addressfortinet
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30