fortinet
36 known vulnerabilities affecting fortinet products.
Products
fortios 23
fortiproxy 13
fortiweb 3
fortipam 3
fortimanager 3
fortimanager_cloud 2
fortiadc 2
fortianalyzer 2
fortisiem 2
fortiswitchmanager 2
fortisandbox 1
fortisandbox_cloud 1
fortisandbox_paas 1
fortisase 1
fortianalyzer_cloud 1
forticlient 1
forticlientems 1
fortigate_6000 1
fortigate_7000 1
fortiportal 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-40684 | Act now | 100.0% | 9.8 | ● | An authentication bypass using an alternate path or channel [CWE-288] in Fortine… |
| CVE-2024-55591 | Act now | 98.3% | 9.8 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2… |
| CVE-2026-35616 | Act now | 90.7% | 9.8 | ● | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through… |
| CVE-2023-27997 | Act now | 85.7% | 9.8 | ● | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an… |
| CVE-2024-21762 | Act now | 84.3% | 9.8 | ● | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th… |
| CVE-2026-25089 | Act now | 76.1% | 9.8 | ● | A improper neutralization of special elements used in an os command ('os command… |
| CVE-2020-12812 | Act now | 49.3% | 9.8 | ● | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6… |
| CVE-2018-13374 | Act now | 37.8% | 4.3 | ● | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC … |
| CVE-2025-68686 | Act now | 29.6% | 5.9 | ● | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE… |
| CVE-2019-5591 | Act now | 18.4% | 6.5 | ● | A Default Configuration vulnerability in FortiOS may allow an unauthenticated at… |
| CVE-2025-24472 | Act now | 7.2% | 8.1 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2… |
| CVE-2019-6693 | Act now | 5.8% | 6.5 | ● | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS config… |
| CVE-2025-25249 | Act now | 2.4% | 8.1 | ● | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6… |
| CVE-2025-25256 | High | 62.8% | 9.8 | An improper neutralization of special elements used in an OS command ('OS Comman… | |
| CVE-2026-40688 | Medium | 6.4% | 7.2 | An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWe… | |
| CVE-2025-31104 | Medium | 1.1% | 7.2 | A improper neutralization of special elements used in an os command ('os command… | |
| CVE-2026-70468 | Medium | 0.7% | 8.1 | A authentication bypass using an alternate path or channel vulnerability in Fort… | |
| CVE-2026-70465 | Medium | 0.7% | 8.1 | A buffer copy without checking size of input ('classic buffer overflow') vulnera… | |
| CVE-2026-26035 | Medium | 0.7% | 9.8 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For… | |
| CVE-2025-61848 | Medium | 0.5% | 7.2 | An improper neutralization of special elements used in an sql command ('sql inje… | |
| CVE-2023-42787 | Low | 1.4% | 6.5 | A client-side enforcement of server-side security [CWE-602] vulnerability in For… | |
| CVE-2026-59837 | Low | 0.7% | 6.6 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.… | |
| CVE-2026-71407 | Low | 0.5% | 5.6 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet … | |
| CVE-2026-71408 | Low | 0.5% | 5.3 | A allocation of resources without limits or throttling vulnerability in Fortinet… | |
| CVE-2023-50176 | Low | 0.4% | 4.2 | A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiO… | |
| CVE-2026-23573 | Low | 0.4% | 6.1 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… | |
| CVE-2025-43892 | Low | 0.4% | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO… | |
| CVE-2025-62826 | Low | 0.4% | 3.1 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl… | |
| CVE-2025-25252 | Low | 0.3% | 4.8 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.… | |
| CVE-2026-59840 | Low | 0.3% | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO… | |
| CVE-2026-70466 | Low | 0.3% | 5.3 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 … | |
| CVE-2025-62675 | Low | 0.3% | 3.4 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl… | |
| CVE-2026-59839 | Low | 0.3% | 5.5 | A improper limitation of a pathname to a restricted directory ('path traversal')… | |
| CVE-2026-70467 | Low | 0.2% | 3.8 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, … | |
| CVE-2026-49938 | Low | 0.2% | 6.5 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.… | |
| CVE-2025-67862 | Low | 0.1% | 6.7 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [C… |