← All vendors

fortinet

36 known vulnerabilities affecting fortinet products.

Products

fortios 23 fortiproxy 13 fortiweb 3 fortipam 3 fortimanager 3 fortimanager_cloud 2 fortiadc 2 fortianalyzer 2 fortisiem 2 fortiswitchmanager 2 fortisandbox 1 fortisandbox_cloud 1 fortisandbox_paas 1 fortisase 1 fortianalyzer_cloud 1 forticlient 1 forticlientems 1 fortigate_6000 1 fortigate_7000 1 fortiportal 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2022-40684 Act now 100.0% 9.8 An authentication bypass using an alternate path or channel [CWE-288] in Fortine…
CVE-2024-55591 Act now 98.3% 9.8 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2…
CVE-2026-35616 Act now 90.7% 9.8 A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through…
CVE-2023-27997 Act now 85.7% 9.8 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an…
CVE-2024-21762 Act now 84.3% 9.8 A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th…
CVE-2026-25089 Act now 76.1% 9.8 A improper neutralization of special elements used in an os command ('os command…
CVE-2020-12812 Act now 49.3% 9.8 An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6…
CVE-2018-13374 Act now 37.8% 4.3 A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC …
CVE-2025-68686 Act now 29.6% 5.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE…
CVE-2019-5591 Act now 18.4% 6.5 A Default Configuration vulnerability in FortiOS may allow an unauthenticated at…
CVE-2025-24472 Act now 7.2% 8.1 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2…
CVE-2019-6693 Act now 5.8% 6.5 Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS config…
CVE-2025-25249 Act now 2.4% 8.1 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6…
CVE-2025-25256 High 62.8% 9.8 An improper neutralization of special elements used in an OS command ('OS Comman…
CVE-2026-40688 Medium 6.4% 7.2 An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWe…
CVE-2025-31104 Medium 1.1% 7.2 A improper neutralization of special elements used in an os command ('os command…
CVE-2026-70468 Medium 0.7% 8.1 A authentication bypass using an alternate path or channel vulnerability in Fort…
CVE-2026-70465 Medium 0.7% 8.1 A buffer copy without checking size of input ('classic buffer overflow') vulnera…
CVE-2026-26035 Medium 0.7% 9.8 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet For…
CVE-2025-61848 Medium 0.5% 7.2 An improper neutralization of special elements used in an sql command ('sql inje…
CVE-2023-42787 Low 1.4% 6.5 A client-side enforcement of server-side security [CWE-602] vulnerability in For…
CVE-2026-59837 Low 0.7% 6.6 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.…
CVE-2026-71407 Low 0.5% 5.6 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet …
CVE-2026-71408 Low 0.5% 5.3 A allocation of resources without limits or throttling vulnerability in Fortinet…
CVE-2023-50176 Low 0.4% 4.2 A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiO…
CVE-2026-23573 Low 0.4% 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2025-43892 Low 0.4% 4.3 A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO…
CVE-2025-62826 Low 0.4% 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl…
CVE-2025-25252 Low 0.3% 4.8 An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.…
CVE-2026-59840 Low 0.3% 4.3 A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO…
CVE-2026-70466 Low 0.3% 5.3 A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 …
CVE-2025-62675 Low 0.3% 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl…
CVE-2026-59839 Low 0.3% 5.5 A improper limitation of a pathname to a restricted directory ('path traversal')…
CVE-2026-70467 Low 0.2% 3.8 A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, …
CVE-2026-49938 Low 0.2% 6.5 A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.…
CVE-2025-67862 Low 0.1% 6.7 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [C…