Fortinet Fortios vulnerabilities
277 known vulnerabilities affecting fortinet/fortios.
Total CVEs
277
CISA KEV
19
actively exploited
Public exploits
24
Exploited in wild
25
Severity breakdown
CRITICAL25HIGH86MEDIUM156LOW10
Vulnerabilities
Page 5 of 14
CVE-2021-36173P3HIGHCVSS 8.8≥ 6.0.0, ≤ 6.0.13≥ 6.2.0, ≤ 6.2.9+3 more2021-12-08
CVE-2021-36173 [HIGH] CWE-787 CVE-2021-36173: A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0
A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.
nvd
CVE-2022-26122P3HIGHCVSS 8.6≥ 6.0.0, ≤ 6.0.15≥ 6.2.0, ≤ 6.2.11+3 more2022-11-02
CVE-2022-26122 [HIGH] CWE-345 CVE-2022-26122: An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64.
nvd
CVE-2023-46718P3HIGHCVSS 7.8≥ 6.0.13, ≤ 6.0.18≥ 6.2.9, ≤ 6.2.17+6 more2025-10-14
CVE-2023-46718 [HIGH] CWE-121 CVE-2023-46718: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
nvd
CVE-2024-26010P3HIGHCVSS 7.5≥ 6.0.0, < 7.0.15≥ 7.2.0, < 7.2.8+7 more2024-06-11
CVE-2024-26010 [HIGH] CWE-121 CVE-2024-26010: A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18,
nvd
CVE-2023-45583P3HIGHCVSS 7.2fixed in 7.2.6≥ 6.2.0, ≤ 6.2.16+4 more2024-05-14
CVE-2023-45583 [HIGH] CWE-134 CVE-2023-45583: A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all vers
nvd
CVE-2025-53744P3HIGHCVSS 7.2≥ 6.4.0, < 7.4.8≥ 7.6.0, < 7.6.3+5 more2025-08-12
CVE-2025-53744 [HIGH] CWE-266 CVE-2025-53744: An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 t
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.
nvd
CVE-2025-22258P3HIGHCVSS 7.2≥ 7.0.2, < 7.0.17≥ 7.2.0, < 7.2.11+6 more2025-10-14
CVE-2025-22258 [HIGH] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2
nvd
CVE-2026-59837P3MEDIUMCVSS 6.6≥ 7.2.0, < 7.4.2≥ 7.4.0, ≤ 7.4.1+3 more2026-07-14
CVE-2026-59837 [MEDIUM] CWE-121 CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all vers
nvd
CVE-2021-24018P3HIGHCVSS 8.8fixed in 6.2.10≥ 6.4.0, < 6.4.7+1 more2021-08-04
CVE-2021-24018 [HIGH] CWE-787 CVE-2021-24018: A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may a
A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network to potentially execute arbitrary code via a specifically crafted firmware image.
nvd
CVE-2022-27491P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.14≥ 6.2.0, < 6.2.11+3 more2022-09-06
CVE-2022-27491 [HIGH] CVE-2022-27491: A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine ver
A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially
nvd
CVE-2023-46720P3HIGHCVSS 7.8≥ 6.0.13, ≤ 6.0.18≥ 6.2.9, ≤ 6.2.16+6 more2024-06-11
CVE-2023-46720 [HIGH] CWE-121 CVE-2023-46720: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
nvd
CVE-2024-46668P3HIGHCVSS 7.5≥ 6.4.0, < 6.4.16≥ 7.0.0, < 7.0.16+6 more2025-01-14
CVE-2024-46668 [HIGH] CWE-770 CVE-2024-46668: An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.
nvd
CVE-2023-44247P3HIGHCVSS 7.2≥ 6.2.0, ≤ 6.2.16≥ 6.4.0, ≤ 6.4.152024-05-14
CVE-2023-44247 [HIGH] CWE-415 CVE-2023-44247: A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
nvd
CVE-2024-50565P3HIGHCVSS 7.5≥ 6.4.0, < 7.0.16≥ 7.2.0, < 7.2.9+6 more2025-04-08
CVE-2024-50565 [HIGH] CWE-300 CVE-2024-50565: A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in For
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, For
nvd
CVE-2024-23110P3HIGHCVSS 7.8≥ 6.0.0, < 6.2.16≥ 6.4.0, < 6.4.15+9 more2024-06-11
CVE-2024-23110 [HIGH] CWE-121 CVE-2024-23110: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6,
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands
nvd
CVE-2025-25253P3HIGHCVSS 7.5≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.3+4 more2025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
nvd
CVE-2022-39948P3HIGHCVSS 7.4≥ 6.0.0, < 7.0.8≥ 7.2.0, < 7.2.4+5 more2023-02-16
CVE-2022-39948 [HIGH] CWE-295 CVE-2022-39948: An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 thr
An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel be
nvd
CVE-2024-45324P3HIGHCVSS 7.2≥ 6.2.0, < 6.2.17≥ 6.4.0, < 6.4.16+8 more2025-03-11
CVE-2024-45324 [HIGH] CWE-134 CVE-2024-45324: A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 throug
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and before 1.3.1, FortiSRA version 1.4.0 t
nvd
CVE-2014-2216P3HIGHCVSS 7.5≤ 4.3.15v4.3.10+9 more2014-08-25
CVE-2014-2216 [HIGH] CVE-2014-2216: The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiG
The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.
nvd
CVE-2019-15705P3HIGHCVSS 7.5≤ 6.0.6≥ 6.2.0, ≤ 6.2.12019-11-27
CVE-2019-15705 [HIGH] CWE-20 CVE-2019-15705: An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
nvd