Fortinet Fortios vulnerabilities
266 known vulnerabilities affecting fortinet/fortios.
Total CVEs
266
CISA KEV
18
actively exploited
Public exploits
19
Exploited in wild
13
Severity breakdown
CRITICAL25HIGH84MEDIUM147LOW10
Vulnerabilities
Page 1 of 14
CVE-2025-64157HIGHCVSS 7.2≥ 7.0.0, < 7.4.10≥ 7.6.0, < 7.6.5+4 more2026-02-10
CVE-2025-64157 [MEDIUM] CWE-134 CVE-2025-64157: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4,
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.
cvelistv5nvd
CVE-2026-22153HIGHCVSS 8.1≥ 7.6.0, < 7.6.5≥ 7.6.0, ≤ 7.6.42026-02-10
CVE-2026-22153 [HIGH] CWE-305 CVE-2026-22153: An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet Forti
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
cvelistv5nvd
CVE-2025-62439MEDIUMCVSS 4.2≥ 7.6.0, ≤ 7.6.4≥ 7.4.0, ≤ 7.4.9+2 more2026-02-10
CVE-2025-62439 [MEDIUM] CWE-940 CVE-2025-62439: An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resou
cvelistv5nvd
CVE-2025-68686MEDIUMCVSS 5.9≥ 6.4.0, < 7.4.7≥ 7.6.0, < 7.6.2+5 more2026-02-10
CVE-2025-68686 [MEDIUM] CWE-200 CVE-2025-68686: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persisten
cvelistv5nvd
CVE-2025-55018MEDIUMCVSS 5.8≥ 6.4.3, ≤ 6.4.16≥ 7.0.0, < 7.4.10+4 more2026-02-10
CVE-2025-55018 [MEDIUM] CWE-444 CVE-2025-55018: An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially craft
cvelistv5nvd
CVE-2026-25815LOWCVSS 3.2≤ 7.6.62026-02-05
CVE-2026-25815 [LOW] CWE-1394 CVE-2026-25815: Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configu
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that the instance of CWE-1394 is not a vulnerability because customers
cvelistv5nvd
CVE-2026-24858CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.18≥ 7.2.0, ≤ 7.2.12+4 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
cvelistv5nvd
CVE-2025-25249CRITICALCVSS 9.8≥ 6.4.0, < 6.4.17≥ 7.0.0, < 7.0.18+6 more2026-01-13
CVE-2025-25249 [HIGH] CWE-122 CVE-2025-25249: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 th
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially craf
cvelistv5nvd
CVE-2024-40593MEDIUMCVSS 4.4v7.0.14v7.2.7+2 more2025-12-11
CVE-2024-40593 [MEDIUM] CWE-320 CVE-2024-40593: A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions, FortiOS 7.6.0, FortiOS 7.4.4, FortiOS
cvelistv5nvd
CVE-2025-59718CRITICALCVSS 9.8KEV≥ 7.0.0, < 7.0.18≥ 7.2.0, < 7.2.12+6 more2025-12-09
CVE-2025-59718 [CRITICAL] CWE-347 CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.
cvelistv5nvd
CVE-2024-47570MEDIUMCVSS 6.6≥ 7.0.4, ≤ 7.0.17≥ 7.2.0, < 7.2.8+3 more2025-12-09
CVE-2024-47570 [MEDIUM] CWE-532 CVE-2024-47570: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only
cvelistv5nvd
CVE-2025-62631MEDIUMCVSS 5.6≥ 6.4.0, < 7.4.1v7.4.0+3 more2025-12-09
CVE-2025-62631 [MEDIUM] CWE-613 CVE-2025-62631: An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0,
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the a
cvelistv5nvd
CVE-2025-53843HIGHCVSS 7.5≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.4+5 more2025-11-18
CVE-2025-53843 [HIGH] CWE-121 CVE-2025-53843: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 t
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets
cvelistv5nvd
CVE-2025-58413HIGHCVSS 7.5≥ 6.0.0, < 7.4.9≥ 7.6.0, < 7.6.4+7 more2025-11-18
CVE-2025-58413 [HIGH] CWE-121 CVE-2025-58413: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 t
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets
cvelistv5nvd
CVE-2025-54821MEDIUMCVSS 6.0≥ 6.4.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+4 more2025-11-18
CVE-2025-54821 [LOW] CWE-269 CVE-2025-54821: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 a
cvelistv5nvd
CVE-2023-46718HIGHCVSS 7.8≥ 6.0.13, ≤ 6.0.18≥ 6.2.9, ≤ 6.2.17+6 more2025-10-14
CVE-2023-46718 [MEDIUM] CWE-121 CVE-2023-46718: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
cvelistv5nvd
CVE-2025-22258HIGHCVSS 7.2≥ 7.0.2, < 7.0.17≥ 7.2.0, < 7.2.11+6 more2025-10-14
CVE-2025-22258 [MEDIUM] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7
cvelistv5nvd
CVE-2024-50571HIGHCVSS 7.2≥ 6.2.0, < 6.4.16≥ 7.0.0, < 7.0.17+8 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
cvelistv5nvd
CVE-2025-57740HIGHCVSS 8.8≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+6 more2025-10-14
CVE-2025-57740 [HIGH] CWE-122 CVE-2025-57740: An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 an
cvelistv5nvd
CVE-2025-25253HIGHCVSS 7.5≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.3+4 more2025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
cvelistv5nvd
1 / 14Next →