CVE-2026-22572
published 2026-03-10CVE-2026-22572: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7…
PriorityP355high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.56%
42.9th percentile
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 7.2.2 < 7.4.8 | 7.4.8 |
| fortinet | fortianalyzer | 7.2.2 – 7.2.12 | — |
| fortinet | fortianalyzer | 7.4.0 – 7.4.7 | — |
| fortinet | fortianalyzer | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortianalyzer | 7.6.0 – 7.6.3 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.2.2 < 7.4.8 | 7.4.8 |
| fortinet | fortimanager | 7.2.2 – 7.2.12 | — |
| fortinet | fortimanager | 7.4.0 – 7.4.7 | — |
| fortinet | fortimanager | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortimanager | 7.6.0 – 7.6.3 | — |
| fortinet | fortimanager_cloud | >= 7.2.2 < 7.4.8 | 7.4.8 |
| fortinet | fortimanager_cloud | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
MFA Bypass in GUI
vendor_fortinet·2026-03-10·CVSS 7.2
CVE-2026-22572 [HIGH] CWE-288 MFA Bypass in GUI
FG-IR-26-090: MFA Bypass in GUI
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
CVEs: CVE-2026-22572
CWEs: CWE-288
CVSS: 7.2 (high)
Affected products: FortiAnalyzer, FortiManager, FortiManagercloud, Fortinet
GHSA
GHSA-x29j-xwrc-hxr3: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7
ghsa_unreviewed·2026-03-10
CVE-2026-22572 [HIGH] CWE-288 GHSA-x29j-xwrc-hxr3: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiAnalyzer Cloud 7.6.0 through 7.6.3, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2.2 through 7.2.10, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11, FortiManager Cloud 7.6.0 through 7.6.3, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2.2 through 7.2.10 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-68482 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-68482 [HIGH] CVE-2025-68482 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68482 :
Fortinet FortiManager vulnerability analysis and mitigation
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
Source : NVD
## 5.9
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Fortinet FortiManager
FortiAnalyzer Virtual Appliances
Has Public Exploit No
Has CISA KEV Exploit No
Wiz
CVE-2025-48418 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2025-48418 [MEDIUM] CVE-2025-48418 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-48418 :
Fortinet FortiManager vulnerability analysis and mitigation
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud 7.0.1 through 7.0.14, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.0 through 7.2.10, FortiManager 7.0.0 through 7.0.14, FortiManager 6.4 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cl
Wiz
CVE-2025-49784 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2025-49784 [MEDIUM] CVE-2025-49784 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-49784 :
FortiAnalyzer Virtual Appliances vulnerability analysis and mitigation
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer-BigData 7.6.0, FortiAnalyzer-BigData 7.4.0 through 7.4.4, FortiAnalyzer-BigData 7.2 all versions, FortiAnalyzer-BigData 7.0 all versions, FortiAnalyzer-BigData 6.4 all versions, FortiAnalyzer-BigData 6.2 all versions may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted requests.
Source : NVD
## 7.2
Score
Published March 10, 2026
Severity HIGH
CNA Score 6
Wiz
CVE-2025-68648 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-68648 [HIGH] CVE-2025-68648 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68648 :
Fortinet FortiManager vulnerability analysis and mitigation
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow an attacker to escalate its privileges via specially crafted r
Wiz
CVE-2026-22629 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-22629 [HIGH] CVE-2026-22629 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22629 :
Fortinet FortiManager vulnerability analysis and mitigation
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4 all versions, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4 all versions, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4 all versions, FortiManager Cloud 7.2 all versions, For
Wiz
CVE-2025-54820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-54820 [HIGH] CVE-2025-54820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-54820 :
Fortinet FortiManager vulnerability analysis and mitigation
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
Source : NVD
## 8.1
Score
Published March 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Fortinet FortiManager
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.9
Exploitation Probability (EPSS) 0.1
Aff
Wiz
CVE-2026-22572 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-22572 [HIGH] CVE-2026-22572 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22572 :
Fortinet FortiManager vulnerability analysis and mitigation
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Source : NVD
## 7.2
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Fortinet FortiManager
FortiAnalyzer Virtual Appliances
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation
2026-03-10
Published