Fortinet Fortiproxy vulnerabilities

121 known vulnerabilities affecting fortinet/fortiproxy.

Total CVEs
121
CISA KEV
12
actively exploited
Public exploits
7
Exploited in wild
8
Severity breakdown
CRITICAL17HIGH39MEDIUM62LOW3

Vulnerabilities

Page 1 of 7
CVE-2026-24858CRITICALCVSS 9.8KEV≥ 7.0.0, ≤ 7.0.22≥ 7.2.0, ≤ 7.2.15+2 more2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.
cvelistv5nvd
CVE-2025-59718CRITICALCVSS 9.8KEV≥ 7.0.0, < 7.0.22≥ 7.2.0, < 7.2.15+6 more2025-12-09
CVE-2025-59718 [CRITICAL] CWE-347 CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7 A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.
cvelistv5nvd
CVE-2024-47570MEDIUMCVSS 6.6≥ 7.2.0, < 7.2.12≥ 7.4.0, < 7.4.4+2 more2025-12-09
CVE-2024-47570 [MEDIUM] CWE-532 CVE-2024-47570: An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only
cvelistv5nvd
CVE-2025-54821MEDIUMCVSS 6.0≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-11-18
CVE-2025-54821 [LOW] CWE-269 CVE-2025-54821: An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 a
cvelistv5nvd
CVE-2023-46718HIGHCVSS 7.8≥ 7.0.0, < 7.4.8≥ 7.4.0, ≤ 7.4.7+2 more2025-10-14
CVE-2023-46718 [MEDIUM] CWE-121 CVE-2023-46718: A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2. A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands.
cvelistv5nvd
CVE-2025-22258HIGHCVSS 7.2≥ 7.4.0, < 7.4.8≥ 7.6.0, < 7.6.2+2 more2025-10-14
CVE-2025-22258 [MEDIUM] CWE-122 CVE-2025-22258: A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7
cvelistv5nvd
CVE-2024-50571HIGHCVSS 7.2≥ 1.0.0, < 7.0.20≥ 7.2.0, < 7.2.13+9 more2025-10-14
CVE-2024-50571 [HIGH] CWE-122 CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnaly A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud
cvelistv5nvd
CVE-2025-57740HIGHCVSS 8.8≥ 7.0.0, < 7.4.4≥ 7.6.0, < 7.6.3+4 more2025-10-14
CVE-2025-57740 [HIGH] CWE-122 CVE-2025-57740: An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7. An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 an
cvelistv5nvd
CVE-2025-25253HIGHCVSS 7.5≥ 7.0.0, < 7.4.9≥ 7.6.0, < 7.6.2+4 more2025-10-14
CVE-2025-25253 [HIGH] CWE-297 CVE-2025-25253: An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy versi An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle posi
cvelistv5nvd
CVE-2025-47890MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-47890 [LOW] CWE-601 CVE-2025-47890: An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6 An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE
cvelistv5nvd
CVE-2024-26008MEDIUMCVSS 5.3≥ 1.2.0, < 7.2.10≥ 7.4.0, < 7.4.4+5 more2025-10-14
CVE-2024-26008 [MEDIUM] CWE-754 CVE-2024-26008: An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7 An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to
cvelistv5nvd
CVE-2025-25255MEDIUMCVSS 4.3≥ 7.0.1, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-25255 [MEDIUM] CWE-358 CVE-2025-25255: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Forti An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via
cvelistv5nvd
CVE-2025-31366MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-31366 [MEDIUM] CWE-79 CVE-2025-31366: An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0
cvelistv5nvd
CVE-2025-54822MEDIUMCVSS 4.3≥ 2.0.0, < 7.4.9≥ 7.4.0, ≤ 7.4.8+3 more2025-10-14
CVE-2025-54822 [MEDIUM] CWE-285 CVE-2025-54822: An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7. An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiProxy 2.0 all versions allows an authenticated attacker to access static files of others VDO
cvelistv5nvd
CVE-2024-47569MEDIUMCVSS 4.3≥ 1.0.0, < 7.2.11≥ 7.4.0, < 7.4.5+3 more2025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
cvelistv5nvd
CVE-2025-31514MEDIUMCVSS 4.3≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-31514 [LOW] CWE-532 CVE-2025-31514: An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command.
cvelistv5nvd
CVE-2025-22862MEDIUMCVSS 6.7≥ 7.0.5, < 7.4.9≥ 7.6.0, < 7.6.3+4 more2025-10-02
CVE-2025-22862 [MEDIUM] CWE-288 CVE-2025-22862: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action
cvelistv5nvd
CVE-2024-26009HIGHCVSS 8.1≥ 7.0.0, < 7.0.16≥ 7.2.0, < 7.2.9+4 more2025-08-12
CVE-2024-26009 [HIGH] CWE-288 CVE-2024-26009: An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet Fort An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS version 6.4.0 through 6.4.15 and before 6.2.16, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8 and before 7.0.15 & FortiPAM before version 1.2.0 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM re
cvelistv5nvd
CVE-2023-45584HIGHCVSS 7.2≥ 7.0.0, < 7.0.14≥ 7.2.0, < 7.2.8+4 more2025-08-12
CVE-2023-45584 [MEDIUM] CWE-415 CVE-2023-45584: A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13 allows a privileged attacker to execu
cvelistv5nvd
CVE-2025-25248MEDIUMCVSS 6.5≥ 2.0.0, < 7.4.4≥ 7.6.0, < 7.6.3+5 more2025-08-12
CVE-2025-25248 [MEDIUM] CWE-190 CVE-2025-25248: An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, versio An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3
cvelistv5nvd