CiberLATAMbywhalemate

Brazil flags Fortinet, Cisco and Adobe flaws

CTIR Gov issued three alerts on Fortinet, Cisco ISE, and Adobe Commerce and Magento. INCIBE-CERT also warned on GitLab

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil's CTIR Gov issued three security alerts over two days, one on multiple Fortinet products, another on Cisco Identity Services Engine, and a third on Adobe Commerce and Magento. At the same time, Spain's INCIBE-CERT published advisories on GitLab and Stockagile vulnerabilities, while Brazil's CISC bulletin noted active exploitation of a Fortinet authentication bypass.

Brazil's CTIR Gov published three security alerts between Sept. 25 and 26 addressing critical flaws in multiple Fortinet products, Cisco Identity Services Engine, and Adobe Commerce and Magento. At the same time, Spain's INCIBE-CERT issued advisories on 11 GitLab vulnerabilities and seven Stockagile flaws, while Brazil's CISC bulletin included active exploitation of a Fortinet authentication bypass.

What did Brazil's CTIR Gov fix?

CTIR Gov issued ALERT 86/2026 for an update that fixes a critical flaw in multiple Fortinet products, ALERT 87/2026 for Cisco Identity Services Engine, and ALERT 85/2026 for Adobe Commerce and Magento. In the last notice, the Brazilian agency said the issue could allow arbitrary code execution and assigned it an EPSS score of 3.95%.

In the Fortinet case, notice 86/2026 identifies CVE-2025-25249, says it affects, among others, FortiOS and FortiSwitchManager, and lists it in the CISA KEV catalog. The same document gives it an EPSS score of 3.86%. Alert 86/2026 was published on Sept. 25, 2026.

What did Brazil's bulletins say about Fortinet?

Brazil's CISC Vulnerabilities bulletin included a section on active exploitation of an authentication bypass in Fortinet devices, identified as CVE-2025-20265. The text explicitly uses the phrase "Exploração Ativa de Bypass de Autenticação em Dispositivos Fortinet (Patch Bypass)," which confirms active exploitation in that notice.

The same bulletin also listed alerts on CVE-2026-42031 in CKAN DataStore, CVE-2026-44277 in Fortinet FortiAuthenticator, six zero-day vulnerabilities in Microsoft Windows, a critical code execution flaw in 7-Zip, an authentication bypass in Check Point Remote Access VPN, and multiple critical vulnerabilities in NGINX.

What happened with GitLab and Stockagile?

INCIBE-CERT published a notice on 11 GitLab vulnerabilities, two of them critical, and recommended updating to GitLab 19.2.7 or later, 19.3.3 or later, and 19.4.1 or later depending on the installed branch. Forest Watch reported that GitLab released emergency patches 19.4.1, 19.3.3, and 19.2.7 for Community and Enterprise, fixing 11 vulnerabilities, including two critical flaws rated CVSS 9.9.

The official CVE records link those critical flaws to CVE-2026-89078, a double free when analyzing a manipulated regular expression in a CI/CD configuration, and CVE-2026-93577, an integer overflow in the same context. In both cases, under certain conditions, an authenticated user could execute arbitrary code on the GitLab server. Another record, CVE-2026-92530, describes an issue that could allow a user to impersonate the author of merge requests during Direct Transfer imports.

In Stockagile, INCIBE-CERT warned about seven medium-severity vulnerabilities and said that, for now, no fix had been reported and no known exploitation attempts had been observed.

What regional scope do these alerts show?

The materials published by CTIR Gov, CISC, and INCIBE-CERT show a recent run of advisories centered on products widely used in corporate and infrastructure environments. Brazil focused on Fortinet, Cisco, and Adobe, while Spain, through INCIBE-CERT, reported on GitLab and Stockagile with update guidance and, in the latter case, no available fix at the time of the notice.

Sources

View all