cbcvebase.

Fortinet Fortimanager vulnerabilities

122 known vulnerabilities affecting fortinet/fortimanager.

Total CVEs
122
CISA KEV
3
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH42MEDIUM59LOW6

Vulnerabilities

Page 1 of 7
CVE-2025-67604MEDIUMCVSS 5.3≥ 7.2.0, ≤ 7.2.12≥ 7.4.0, < 7.4.9+5 more2026-05-12
CVE-2025-67604 [MEDIUM] CWE-676 CVE-2025-67604: A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all
nvd
CVE-2026-22828HIGHCVSS 8.12026-04-14
CVE-2026-22828 [HIGH] CWE-122 Heap-based buffer overflow in oftpd daemon FG-IR-26-121: Heap-based buffer overflow in oftpd daemon A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentatio
fortinet
CVE-2025-61848HIGHCVSS 7.2≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.5+1 more2026-04-14
CVE-2025-61848 [HIGH] CWE-89 CVE-2025-61848: An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2
nvdfortinet
CVE-2025-68649MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-04-14
CVE-2025-68649 [MEDIUM] CWE-22 CVE-2025-68649: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all
nvdfortinet
CVE-2025-48418HIGHCVSS 7.2≥ 6.4.0, < 7.0.15≥ 7.2.0, < 7.2.11+7 more2026-03-10
CVE-2025-48418 [HIGH] CWE-912 CVE-2025-48418: A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7. A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud
nvdfortinet
CVE-2025-54820HIGHCVSS 8.1≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.3+3 more2026-03-10
CVE-2025-54820 [HIGH] CWE-121 CVE-2025-54820: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 t A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability
nvdfortinet
CVE-2025-68648HIGHCVSS 7.2≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-03-10
CVE-2025-68648 [HIGH] CWE-134 CVE-2025-68648: A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7 A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, Fort
nvdfortinet
CVE-2026-22572HIGHCVSS 7.2≥ 7.2.2, < 7.4.8≥ 7.6.0, < 7.6.4+3 more2026-03-10
CVE-2026-22572 [HIGH] CWE-288 CVE-2026-22572: An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password
nvdfortinet
CVE-2025-68482MEDIUMCVSS 5.9≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.5+5 more2026-03-10
CVE-2025-68482 [MEDIUM] CWE-295 CVE-2025-68482: A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, Forti A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versi
nvdfortinet
CVE-2026-22629LOWCVSS 3.7≥ 6.4.0, < 7.6.5≥ 7.6.0, ≤ 7.6.4+4 more2026-03-10
CVE-2026-22629 [LOW] CWE-307 CVE-2026-22629: An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4 all versions, FortiAnalyzer Cloud 7.2 a
nvdfortinet
CVE-2026-24858CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.15≥ 7.2.0, ≤ 7.2.11+4 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
nvdfortinet
CVE-2024-40593MEDIUMCVSS 4.4≥ 6.4.0, < 7.2.6≥ 7.4.0, < 7.4.3+4 more2025-12-11
CVE-2024-40593 [MEDIUM] CWE-320 CVE-2024-40593: A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7 A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS
nvdfortinet
CVE-2024-50571HIGHCVSS 7.2≥ 6.0.0, < 7.0.14≥ 7.2.0, < 7.2.10+9 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
nvdfortinet
CVE-2024-47569MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.4≥ 7.6.0, < 7.6.2+1 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvdfortinet
CVE-2025-53744HIGHCVSS 7.22025-08-12
CVE-2025-53744 [HIGH] CWE-266 Incorrect Privilege Assignment in Security Fabric FG-IR-25-173: Incorrect Privilege Assignment in Security Fabric An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager. CV
fortinet
CVE-2024-26009HIGHCVSS 8.12025-08-12
CVE-2024-26009 [HIGH] CWE-288 Weak authentication - FGFM protocol FG-IR-24-042: Weak authentication - FGFM protocol An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6.4.0 through 6.4.15 and before 6.2.16, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8 and before 7.0.15 & FortiPAM before version 1.2.0 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is manag
fortinet
CVE-2024-52964MEDIUMCVSS 6.5≥ 6.2.0, < 7.0.14≥ 7.2.0, < 7.2.10+8 more2025-08-12
CVE-2024-52964 [MEDIUM] CWE-22 CVE-2024-52964: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overw
nvdfortinet
CVE-2025-24474LOWCVSS 2.7≥ 6.4.0, < 7.4.7≥ 7.6.0, < 7.6.2+5 more2025-07-08
CVE-2025-24474 [LOW] CWE-89 CVE-2025-24474: An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabilit An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiAnalyzer 7.6.0 through 7.6.1, 7.4
nvdfortinet
CVE-2024-54020MEDIUMCVSS 4.3≥ 7.0.0, < 7.0.8≥ 7.2.0, < 7.2.2+2 more2025-05-28
CVE-2024-54020 [MEDIUM] CWE-862 CVE-2024-54020: A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 th A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests.
nvdfortinet
CVE-2024-50565HIGHCVSS 7.5≥ 6.2.0, < 6.2.14≥ 6.4.0, < 6.4.15+3 more2025-04-08
CVE-2024-50565 [HIGH] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, For
nvd