Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 3 of 14
CVE-2016-3978P3MEDIUMCVSS 6.1PoCv5.0.0v5.0.1+15 more2016-04-08
CVE-2016-3978 [MEDIUM] CWE-79 CVE-2016-3978: The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before
The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."
nvd
CVE-2025-57740P3HIGHCVSS 8.8≥ 6.4.0, < 7.2.11≥ 7.4.0, < 7.4.8+6 more2025-10-14
CVE-2025-57740 [HIGH] CWE-122 CVE-2025-57740: An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 an
nvd
CVE-2005-3058P3HIGHCVSS 7.5PoC≤ 2.8_mr10≤ 3_beta2005-12-31
CVE-2005-3058 [HIGH] CWE-264 CVE-2005-3058: Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
nvd
CVE-2024-26009P3HIGHCVSS 8.1≥ 6.0.0, < 6.2.17≥ 6.4.0, < 6.4.16+3 more2025-08-12
CVE-2024-26009 [HIGH] CWE-288 CVE-2024-26009: An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet Fort
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15
nvd
CVE-2017-3131P3MEDIUMCVSS 5.4PoCv5.4.0v5.4.1+4 more2017-09-12
CVE-2017-3131 [MEDIUM] CWE-79 CVE-2017-3131: A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allo
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.
nvd
CVE-2025-25249P3CRITICALCVSS 9.8≥ 6.4.0, < 6.4.17≥ 7.0.0, < 7.0.18+6 more2026-01-13
CVE-2025-25249 [CRITICAL] CWE-122 CVE-2025-25249: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 th
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially
nvd
CVE-2023-28001P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.12≥ 7.2.0, ≤ 7.2.42023-07-11
CVE-2023-28001 [CRITICAL] CWE-613 CVE-2023-28001: An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an at
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API.
nvd
CVE-2023-22640P3HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.16≥ 6.2.0, < 6.2.14+7 more2023-05-03
CVE-2023-22640 [HIGH] CWE-787 CVE-2023-22640: A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0, FortiProxy all versions 1.2, Fort
nvd
CVE-2025-53847P3HIGHCVSS 8.8≥ 6.2.9, < 7.0.18≥ 7.2.0, < 7.2.12+8 more2026-04-14
CVE-2025-53847 [HIGH] CWE-306 CVE-2025-53847: A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
nvd
CVE-2023-50176P3HIGHCVSS 8.8≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.8+4 more2024-11-12
CVE-2023-50176 [HIGH] CWE-384 CVE-2023-50176: A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
nvd
CVE-2024-35279P3HIGHCVSS 8.1≥ 7.2.4, < 7.2.9≥ 7.4.0, < 7.4.5+2 more2025-02-11
CVE-2024-35279 [HIGH] CWE-121 CVE-2024-35279: A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack protections and provided the fabr
nvd
CVE-2015-7361P3CRITICALCVSS 9.3v5.2.32015-10-15
CVE-2015-7361 [CRITICAL] CWE-287 CVE-2015-7361: FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.
nvd
CVE-2023-41678P3HIGHCVSS 8.8v7.0.0v7.0.1+5 more2023-12-13
CVE-2023-41678 [HIGH] CWE-415 CVE-2023-41678: A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
nvd
CVE-2020-12820P3HIGHCVSS 8.8fixed in 5.6.13≥ 6.0.0, < 6.0.11+2 more2024-12-19
CVE-2020-12820 [HIGH] CWE-121 CVE-2020-12820: Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below,
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClient file name. We are not aware of proof of concept code
nvd
CVE-2023-36639P3HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.17≥ 6.2.0, ≤ 6.2.15+4 more2023-12-13
CVE-2023-36639 [HIGH] CWE-134 CVE-2023-36639: A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.
A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0 through 1.0.3 allows attacker to execute unauthorized code or commands via s
nvd
CVE-2022-45862P3HIGHCVSS 8.8≥ 6.4.0, < 7.2.6≥ 7.2.0, ≤ 7.2.5+2 more2024-08-13
CVE-2022-45862 [HIGH] CWE-613 CVE-2022-45862: An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below,
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; FortiPAM 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions; FortiSwitchManager 7.2.1 and below, 7.0 all versions GUI may allow attackers to re-use w
nvd
CVE-2025-53843P3HIGHCVSS 7.5≥ 6.4.0, < 7.4.9≥ 7.6.0, < 7.6.4+5 more2025-11-18
CVE-2025-53843 [HIGH] CWE-121 CVE-2025-53843: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 t
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets
nvd
CVE-2023-29181P3HIGHCVSS 8.8≥ 6.0.0, < 6.2.15≥ 6.4.0, < 6.4.13+15 more2024-02-22
CVE-2023-29181 [HIGH] CWE-134 CVE-2023-29181: A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through
A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM 1.0.0 through 1.0.3 allows atta
nvd
CVE-2023-37930P3HIGHCVSS 8.8≥ 6.4.7, < 6.4.15≥ 7.0.1, < 7.0.13+5 more2025-04-08
CVE-2023-37930 [HIGH] CWE-908 CVE-2023-37930: Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
nvd
CVE-2022-43947P3HIGHCVSS 8.8≥ 6.2.0, < 6.4.13≥ 7.0.0, < 7.0.11+5 more2023-04-11
CVE-2022-43947 [HIGH] CWE-307 CVE-2022-43947: An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet For
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.10, FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 administrative interface allows an attacker with a valid user account to perform brute-force attacks on other user accounts via injecting valid l
nvd