Brazil flags Fortinet, Cisco and Adobe flaws
CTIR Gov issued three alerts on Fortinet, Cisco ISE, and Adobe Commerce and Magento. INCIBE-CERT also warned on GitLab
Brazil's CTIR Gov issued three security alerts over two days, one on multiple Fortinet products, another on Cisco Identity Services Engine, and a third on Adobe Commerce and Magento. At the same time, Spain's INCIBE-CERT published advisories on GitLab and Stockagile vulnerabilities, while Brazil's CISC bulletin noted active exploitation of a Fortinet authentication bypass.
Brazil's CTIR Gov published three security alerts between Sept. 25 and 26 addressing critical flaws in multiple Fortinet products, Cisco Identity Services Engine, and Adobe Commerce and Magento. At the same time, Spain's INCIBE-CERT issued advisories on 11 GitLab vulnerabilities and seven Stockagile flaws, while Brazil's CISC bulletin included active exploitation of a Fortinet authentication bypass.
What did Brazil's CTIR Gov fix?
CTIR Gov issued ALERT 86/2026 for an update that fixes a critical flaw in multiple Fortinet products, ALERT 87/2026 for Cisco Identity Services Engine, and ALERT 85/2026 for Adobe Commerce and Magento. In the last notice, the Brazilian agency said the issue could allow arbitrary code execution and assigned it an EPSS score of 3.95%.
In the Fortinet case, notice 86/2026 identifies CVE-2025-25249, says it affects, among others, FortiOS and FortiSwitchManager, and lists it in the CISA KEV catalog. The same document gives it an EPSS score of 3.86%. Alert 86/2026 was published on Sept. 25, 2026.
What did Brazil's bulletins say about Fortinet?
Brazil's CISC Vulnerabilities bulletin included a section on active exploitation of an authentication bypass in Fortinet devices, identified as CVE-2025-20265. The text explicitly uses the phrase "Exploração Ativa de Bypass de Autenticação em Dispositivos Fortinet (Patch Bypass)," which confirms active exploitation in that notice.
The same bulletin also listed alerts on CVE-2026-42031 in CKAN DataStore, CVE-2026-44277 in Fortinet FortiAuthenticator, six zero-day vulnerabilities in Microsoft Windows, a critical code execution flaw in 7-Zip, an authentication bypass in Check Point Remote Access VPN, and multiple critical vulnerabilities in NGINX.
What happened with GitLab and Stockagile?
INCIBE-CERT published a notice on 11 GitLab vulnerabilities, two of them critical, and recommended updating to GitLab 19.2.7 or later, 19.3.3 or later, and 19.4.1 or later depending on the installed branch. Forest Watch reported that GitLab released emergency patches 19.4.1, 19.3.3, and 19.2.7 for Community and Enterprise, fixing 11 vulnerabilities, including two critical flaws rated CVSS 9.9.
The official CVE records link those critical flaws to CVE-2026-89078, a double free when analyzing a manipulated regular expression in a CI/CD configuration, and CVE-2026-93577, an integer overflow in the same context. In both cases, under certain conditions, an authenticated user could execute arbitrary code on the GitLab server. Another record, CVE-2026-92530, describes an issue that could allow a user to impersonate the author of merge requests during Direct Transfer imports.
In Stockagile, INCIBE-CERT warned about seven medium-severity vulnerabilities and said that, for now, no fix had been reported and no known exploitation attempts had been observed.
What regional scope do these alerts show?
The materials published by CTIR Gov, CISC, and INCIBE-CERT show a recent run of advisories centered on products widely used in corporate and infrastructure environments. Brazil focused on Fortinet, Cisco, and Adobe, while Spain, through INCIBE-CERT, reported on GitLab and Stockagile with update guidance and, in the latter case, no available fix at the time of the notice.
Sources
- ALERTA 87/2026gov.br· Governo Federal do Brasil / CTIR Gov
- CVE-2026-92530 - CVE Recordcve.org· CVE.org
- INCIBE-CERT alerta de siete vulnerabilidades de severidad mediamoncloa.com· Moncloa
- 「GitLab」に再び緊急パッチ、CVSS基本値「9.9」の脆弱性2件に対処forest.watch.impress.co.jp· Forest Watch / Impress Watch
- CVE-2026-89078 - CVE Recordcve.org· CVE.org
- ALERTA 85/2026gov.br· Governo Federal do Brasil / CTIR Gov
- ALERTA 86/2026 — Vulnerabilidade crítica que afeta múltiplos produtos Fortinetgov.br· Governo Federal do Brasil / CTIR Gov
- Boletim do CISC de Vulnerabilidadesgov.br· Governo Federal do Brasil / CISC
- ALERTA 86/2026gov.br· Governo Federal do Brasil / CTIR Gov
- CVE-2026-93577 - CVE Recordcve.org· CVE.org
- INCIBE-CERT alerta de 11 vulnerabilidades en GitLab, dos de severidad críticamoncloa.com· Moncloa



