CVE-2025-54820
published 2026-03-10CVE-2025-54820: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10…
PriorityP264high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.87%
55.1th percentile
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 7.2.11 | 7.2.11 |
| fortinet | fortimanager | 6.4.0 – 6.4.15 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.10 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.3 | 7.4.3 |
| fortinet | fortimanager | 7.4.0 – 7.4.2 | — |
| fortinet | fortinet | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via crafted requests to the 'fgtupdates' service on FortiManager. Detection should focus on anomalous or malformed requests targeting this service. ↗
- →The advisory title 'Buffer overflow via fgtupdates service' identifies 'fgtupdates' as the specific vulnerable service. Monitor for unexpected activity or connections to/from this service on FortiManager instances. ↗
- →Exploitation requires bypassing stack protection mechanisms (e.g., stack canaries, ASLR). Look for crash/core dump artifacts or unexpected process termination of the fgtupdates service as indicators of exploitation attempts. ↗
- ·The vulnerability only applies if the fgtupdates service is enabled on the FortiManager instance. Disabling the service removes the attack surface. ↗
- ·Affected versions are FortiManager 7.4.0–7.4.2, 7.2.0–7.2.10, and 6.4 all versions. FortiManager 7.4.3+ and 7.2.11+ are not listed as affected. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Buffer overflow via fgtupdates service
vendor_fortinet·2026-03-10·CVSS 8.1
CVE-2025-54820 [HIGH] CWE-121 Buffer overflow via fgtupdates service
FG-IR-26-098: Buffer overflow via fgtupdates service
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
CVEs: CVE-2025-54820
CWEs: CWE-121, CWE-787
CVSS: 8.1 (high)
Affected products: FortiManager, Fortinet
GHSA
GHSA-qq5m-xh4x-hv7f: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7
ghsa_unreviewed·2026-03-10
CVE-2025-54820 [HIGH] CWE-121 GHSA-qq5m-xh4x-hv7f: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-68482 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-68482 [HIGH] CVE-2025-68482 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68482 :
Fortinet FortiManager vulnerability analysis and mitigation
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
Source : NVD
## 5.9
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Fortinet FortiManager
FortiAnalyzer Virtual Appliances
Has Public Exploit No
Has CISA KEV Exploit No
Wiz
CVE-2025-48418 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2025-48418 [MEDIUM] CVE-2025-48418 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-48418 :
Fortinet FortiManager vulnerability analysis and mitigation
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud 7.0.1 through 7.0.14, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.0 through 7.2.10, FortiManager 7.0.0 through 7.0.14, FortiManager 6.4 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cl
Wiz
CVE-2025-68648 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-68648 [HIGH] CVE-2025-68648 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68648 :
Fortinet FortiManager vulnerability analysis and mitigation
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow an attacker to escalate its privileges via specially crafted r
Wiz
CVE-2026-22629 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-22629 [HIGH] CVE-2026-22629 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22629 :
Fortinet FortiManager vulnerability analysis and mitigation
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4 all versions, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4 all versions, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4 all versions, FortiManager Cloud 7.2 all versions, For
Wiz
CVE-2025-54820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-54820 [HIGH] CVE-2025-54820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-54820 :
Fortinet FortiManager vulnerability analysis and mitigation
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
Source : NVD
## 8.1
Score
Published March 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Fortinet FortiManager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.9
Exploitation Probability (EPSS) 0.1
Aff
Wiz
CVE-2026-22572 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-22572 [HIGH] CVE-2026-22572 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22572 :
Fortinet FortiManager vulnerability analysis and mitigation
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Source : NVD
## 7.2
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Fortinet FortiManager
FortiAnalyzer Virtual Appliances
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation
2026-03-10
Published