Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Fortinet

Vulnerabilities in FortiOS, FortiGate, and FortiProxy — the firewall and SSL-VPN appliances that sit at the network edge, making a single auth-bypass or overflow bug a direct path to full network compromise.

31 CVEs4 articlesRSS
CVEs
CVE-2026-26035
[ CRITICAL ]CVSS 9.8EPSS 0.5%patched

FortiWeb Authentication Bypass Allows Unauthenticated Login

An improper authentication flaw in FortiWeb lets remote unauthenticated attackers log in with any credentials. Affects versions 7.0.x through 8.0.x; patch available.

Fortinet / FortiWeb
CVE-2026-70468
[ HIGH ]CVSS 8.1EPSS 0.6%patched

FortiManager Authentication Bypass via Alternate Path

Authentication bypass in FortiManager 7.2.5 through 7.6.1 (and cloud variants) allows unauthorized access to the central management plane. CVSS 8.1, patch available.

Fortinet / FortiManager
CVE-2026-25089
[ CRITICAL ]CVSS 9.8EPSS 73.6%kev

Fortinet FortiSandbox unauthenticated OS command injection (4.2, 4.4, 5.0, Cloud, PaaS)

An unauthenticated OS command injection across FortiSandbox 4.2, 4.4, 5.0, plus FortiSandbox Cloud and PaaS 5.0 lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS (multiple 4.x and 5.0 lines — see body)
CVE-2026-39808
[ CRITICAL ]CVSS 9.8EPSS 91.2%kev

Fortinet FortiSandbox unauthenticated OS command injection (4.4 branch and PaaS)

An unauthenticated OS command injection in Fortinet FortiSandbox 4.4.0–4.4.8 and a range of FortiSandbox PaaS builds lets a network attacker run arbitrary commands via crafted HTTP requests. CVSS 9.8; CISA-listed KEV.

Fortinet / FortiSandbox (4.4 branch and multiple PaaS builds — see body)
CVE-2026-21643
[ CRITICAL ]CVSS 9.8EPSS 94.1%kev

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Fortinet / FortiClient EMS
CVE-2026-35616
[ CRITICAL ]CVSS 9.8EPSS 88.9%kev

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Fortinet / FortiClient EMS
CVE-2025-68686
[ MEDIUM ]CVSS 5.9EPSS 1.3%kev

FortiOS patch bypass re-enables symbolic link persistence on compromised devices

FortiOS 7.0–7.6 patch bypass restores symbolic link persistence on already-compromised devices via crafted HTTP requests. Added to CISA KEV July 2026.

Fortinet / FortiOS
CVE-2026-24858
[ CRITICAL ]CVSS 9.8EPSS 85.8%kev

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Fortinet / Multiple Products
CVE-2025-59718
[ CRITICAL ]CVSS 9.8EPSS 63.4%kev

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

Fortinet / Multiple Products
CVE-2025-58034
[ HIGH ]CVSS 7.2EPSS 55.6%kev

Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Fortinet / FortiWeb
CVE-2025-64446
[ CRITICAL ]CVSS 9.8EPSS 91.8%kev

Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Fortinet / FortiWeb
CVE-2025-25257
[ CRITICAL ]CVSS 9.8EPSS 96.7%kev

Fortinet FortiWeb SQL Injection Vulnerability

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet / FortiWeb
CVE-2019-6693
[ MEDIUM ]CVSS 6.5EPSS 5.6%kev

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

Fortinet / FortiOS
CVE-2025-32756
[ CRITICAL ]CVSS 9.8EPSS 29.8%kev

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

Fortinet / Multiple Products
CVE-2025-24472
[ HIGH ]CVSS 8.1EPSS 3.6%kev

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

Fortinet / FortiOS and FortiProxy
CVE-2024-55591
[ CRITICAL ]CVSS 9.8EPSS 98.3%kev

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Fortinet / FortiOS and FortiProxy
CVE-2024-47575
[ CRITICAL ]CVSS 9.8EPSS 95.0%kev

Fortinet FortiManager Missing Authentication Vulnerability

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

Fortinet / FortiManager
CVE-2024-23113
[ CRITICAL ]CVSS 9.8EPSS 61.7%kev

Fortinet Multiple Products Format String Vulnerability

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

Fortinet / Multiple Products
CVE-2023-48788
[ CRITICAL ]CVSS 9.8EPSS 97.6%kev

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

Fortinet / FortiClient EMS
CVE-2024-21762
[ CRITICAL ]CVSS 9.8EPSS 84.3%kev

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.

Fortinet / FortiOS
CVE-2023-27997
[ CRITICAL ]CVSS 9.8EPSS 85.7%kev

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.

Fortinet / FortiOS and FortiProxy SSL-VPN
CVE-2022-41328
[ MEDIUM ]CVSS 6.7EPSS 11.9%kev

Fortinet FortiOS Path Traversal Vulnerability

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

Fortinet / FortiOS
CVE-2022-42475
[ CRITICAL ]CVSS 9.8EPSS 99.5%kev

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Fortinet / FortiOS
CVE-2022-40684
[ CRITICAL ]EPSS 100.0%kev

FortiOS / FortiProxy Authentication Bypass on Administrative Interface

An authentication-bypass vulnerability in FortiOS, FortiProxy, and FortiSwitchManager allows a remote attacker to perform administrative operations on the management interface via crafted HTTP(S) requests, including adding a new administrator SSH key for persistent access.

Fortinet / FortiOS / FortiProxy
CVE-2018-13374
[ MEDIUM ]CVSS 4.3EPSS 38.1%kev

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

Fortinet / FortiOS and FortiADC
CVE-2018-13382
[ CRITICAL ]CVSS 9.1EPSS 81.7%kev

Fortinet FortiOS and FortiProxy Improper Authorization

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Fortinet / FortiOS and FortiProxy
CVE-2018-13383
[ MEDIUM ]CVSS 4.3EPSS 33.6%kev

Fortinet FortiOS and FortiProxy Out-of-bounds Write

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

Fortinet / FortiOS and FortiProxy
CVE-2021-44168
[ LOW ]CVSS 3.3EPSS 0.9%kev

Fortinet FortiOS Arbitrary File Download

Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.

Fortinet / FortiOS
CVE-2018-13379
[ CRITICAL ]CVSS 9.1EPSS 100.0%kev

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

Fortinet / FortiOS
CVE-2019-5591
[ MEDIUM ]CVSS 6.5EPSS 18.4%kev

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

Fortinet / FortiOS
CVE-2020-12812
[ CRITICAL ]CVSS 9.8EPSS 49.3%kev

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

Fortinet / FortiOS
Articles