Supers override fails to properly override supervisor address
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00
CSIRTS triage
- What
- An improper restriction vulnerability may allow an attacker to execute arbitrary code.
- Who is affected
- Users of FortiSIEM Windows Agent on the same local network.
- Urgency
- Remediation is necessary due to the potential for arbitrary code execution.
- Action
- Review and apply any available updates or mitigations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FortiSIEM Windows Agent
Get an email when a new FortiSIEM Windows Agent advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-155
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-598410.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59841 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Fortinet FortiSIEM: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0240 [1.00] [M/H] Vulnerabilities fixed in multiple Fortinet productsncsc-nl
- unknownMultiple vulnerabilities in Fortinet products (July 15, 2026)cert-fr-avis
- highCVE-2026-59841: A improper restriction of communication channel to intended endpoints vulnerability in Fortine…nvd
More from Fortinet FortiGuard PSIRT
- unknownHeader injection in captive portal authentication form2026-07-14
- unknownBuffer overread in authd and wad daemon2026-07-14
- unknownStack Buffer Overflow in Log Report2026-07-14
- unknownOut of bounds read in GUI2026-07-14
- unknownUnauthenticated VNC access exposed on all interfaces2026-07-14