CiberLATAMbywhalemate

Brazil flags Fortinet bypass, critical CVEs

Brazil’s CISC/MJSP bulletin cited active Fortinet exploitation, CVE-2025-20265, and alerts tied to .gov.br domains.

Whalemate Labs · AI-assisted researchPublished:2 min read

The CISC/MJSP Vulnerability Bulletin, published on October 6, 2026 on gov.br, added alerts about active exploitation of an authentication bypass in Fortinet devices and cited CVE-2025-20265, rated CVSS 10.0. The official document also listed other threats, including TOOLSHELL on SharePoint, a CrowdStrike issue and a campaign targeting .gov.br domains.

The CISC/MJSP Vulnerability Bulletin, published on October 6, 2026 on gov.br, added alerts about active exploitation of an authentication bypass in Fortinet devices and cited CVE-2025-20265, rated CVSS 10.0. The official roundup also included other threats affecting products and services used in Brazil, including SharePoint, CrowdStrike, CKAN DataStore and FortiAuthenticator.

What did the Brazilian official bulletin report?

The CISC/MJSP bulletin brought several cybersecurity alerts for Brazil into a single document. Alongside the Fortinet authentication bypass under active exploitation and CVE-2025-20265, the official text listed "Zero-Days TOOLSHELL - SharePoint Servers," a product update flaw in CrowdStrike, a campaign targeting .gov.br domains, CVE-2026-42031 and CVE-2026-44277.

What other cases were listed?

The bulletin also included CVE-2026-42031, described as an SQL injection in CKAN DataStore, and CVE-2026-44277, defined as improper access control in Fortinet FortiAuthenticator. In parallel, The Hacker News reported that Fortinet had issued advisories on critical vulnerabilities in FortiAuthenticator and other products, and linked CVE-2026-44277 to a flaw that could potentially be exploited by an unauthenticated attacker.

What is the scope of those references?

The available material shows that the official bulletin was not limited to a single brand or attack vector. It gathered findings on multiple products and a campaign focused on .gov.br domains. The Fortinet reference in The Hacker News is narrower: the available excerpt identifies CVE-2026-44277 and notes possible exploitation by an unauthenticated attacker, but does not confirm active exploitation or provide details on affected versions or mitigations.

Sources

View all