Vendor

Fortinet vulnerabilities

356 advisories tracked, 31 exploited in the wild according to CISA, 106 published in 2026.

Data refreshed 10 Oct 2026

Patch now

Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).

Show all 30Show fewer

Products covered

Select a product to see only its advisories.

All tracked advisories

Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

PublishedCVEProductIssueSeverityEPSSExploited
CVE-2026-104286Full analysisFortiMailFortiMail Path TraversalCRITICAL 9.82.2%Yes
CVE-2026-84388Other security productsImproper restriction of rendered ui layers or frames in FortiPAM Chrome ExtensionCRITICAL 9.10.38%–
CVE-2026-84392FortiOSNULL Pointer Dereference in FortiOS, FortiProxy and othersLOW 2.50.50%–
CVE-2026-22575FortiManager and FortiAnalyzerImproper access control in FortiManager, FortiManager CloudMEDIUM 4.70.24%–
CVE-2026-84391FortiManager and FortiAnalyzerUse of uninitialized variable in FortiAnalyzerMEDIUM 5.90.41%–
CVE-2026-84393FortiOSImproper validation of certificate with host mismatch in FortiOS, FortiProxyHIGH 7.30.25%–
CVE-2026-26084FortiSandboxImproper access control in FortiSandbox PaaS, FortiSandbox and othersHIGH 8.90.39%–
CVE-2026-84385Other security productsImproper access control in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 4.90.23%–
CVE-2026-84389FortiSIEMOpen redirect in FortiSIEMLOW 2.80.22%–
CVE-2026-84387FortiSandboxCommand injection in FortiSandboxMEDIUM 6.71.4%–
CVE-2026-84386FortiClient and EMSUnverified ownership in FortiClientWindowsMEDIUM 4.70.14%–
CVE-2026-70468FortiManager and FortiAnalyzerAuthentication bypass using an alternate path or channel in FortiManager, FortiManager CloudHIGH 7.30.46%–
CVE-2026-26035FortiWebImproper Authentication in FortiWebHIGH 8.80.75%–
CVE-2026-70466FortiOSIncomplete list of disallowed inputs in FortiWeb, FortiOSMEDIUM 4.80.31%–
CVE-2026-71407FortiOSStack-based Buffer Overflow in FortiOS, FortiPAM and othersMEDIUM 5.10.42%–
CVE-2026-70467FortiSIEMServer-side request forgery (ssrf) in FortiSIEMLOW 3.40.26%–
CVE-2026-71408FortiOSAllocation of resources without limits or throttling in FortiOSMEDIUM 50.40%–
CVE-2026-70465FortiClient and EMSClassic buffer overflow in FortiClientWindowsHIGH 7.30.52%–
CVE-2026-59838FortiSIEMImproper neutralization of script-related html tags in a web page (basic xss) in FortiSIEMMEDIUM 5.30.24%–
CVE-2026-59840FortiOSBuffer over-read in FortiOS, FortiPAM and othersMEDIUM 4.10.31%–
CVE-2025-43892FortiOSBuffer over-read in FortiOSMEDIUM 4.10.38%–
CVE-2026-23573FortiOSCross-site scripting in FortiOS, FortiProxy and othersMEDIUM 6.10.39%–
CVE-2026-59839FortiOSPath traversal in FortiProxy, FortiOS and othersMEDIUM 50.25%–
CVE-2025-62826FortiOSHTTP response splitting in FortiPAM, FortiProxy and othersLOW 3.10.37%–
CVE-2025-62675FortiOSHTTP response splitting in FortiOS, FortiPAM and othersLOW 3.40.27%–
CVE-2026-59836FortiClient and EMSImproper certificate validation in FortiClientEMSMEDIUM 6.70.22%–
CVE-2026-59841FortiSIEMImproper restriction of communication channel to intended endpoints in FortiSIEMWindowsAgentMEDIUM 6.90.24%–
CVE-2025-53379Other security productsOut-of-bounds read in FortiAuthenticatorHIGH 70.53%–
CVE-2026-59835FortiSandboxExposure of resource to wrong sphere in FortiSandboxHIGH 7.70.40%–
CVE-2026-59837FortiOSStack-based buffer overflow in FortiPAM, FortiSASE and othersMEDIUM 5.90.67%–
CVE-2025-67862FortiOSInternal Asset Exposed to Unsafe Debug Access Level or State in FortiOS, FortiProxyMEDIUM 60.15%–
CVE-2026-25089FortiSandboxFortiSandbox OS Command InjectionCRITICAL 9.176%Yes
CVE-2026-49938FortiManager and FortiAnalyzerImproper access control in FortiPortalMEDIUM 6.20.34%–
CVE-2025-53870Other security productsOS command injection in FortiAP, FortiAP-W2MEDIUM 6.50.56%–
CVE-2025-53680Other security productsOS command injection in FortiAP-U, FortiAP-W2 and othersMEDIUM 6.10.56%–
CVE-2025-67604FortiManager and FortiAnalyzerUse of potentially dangerous function in FortiAnalyzer, FortiManagerMEDIUM 5.20.42%–
CVE-2025-53681FortiMailSQL injection& in FortiMailMEDIUM 6.30.36%–
CVE-2026-25690Other security productsArgument injection in FortiDeceptorMEDIUM 40.33%–
CVE-2025-53844FortiOSOut-of-bounds write in FortiOSHIGH 8.30.56%–
CVE-2026-44278FortiClient and EMSUse of hard-coded cryptographic key in FortiClientWindowsLOW 2.10.14%–
CVE-2026-25088Other security productsSQL injection in FortiNDRMEDIUM 5.10.26%–
CVE-2026-44277Other security productsImproper access control in FortiAuthenticatorCRITICAL 9.10.48%–
CVE-2026-26083FortiSandboxMissing authorization in FortiSandbox, FortiSandbox PaaS and othersCRITICAL 9.10.50%–
CVE-2026-40688FortiWebOut-of-bounds write in FortiWebMEDIUM 6.70.88%–
CVE-2025-61624FortiOSPath traversal in FortiOS, FortiProxy and othersMEDIUM 5.40.50%–
CVE-2025-68649FortiManager and FortiAnalyzerPath traversal in FortiManager Cloud, FortiManager and othersMEDIUM 5.40.41%–
CVE-2026-21741FortiNACOpen redirect in FortiNAC-FLOW 2.20.21%–
CVE-2026-39813FortiSandbox'../filedir' in FortiSandbox, FortiSandbox CloudCRITICAL 9.10.72%–
CVE-2025-61848FortiManager and FortiAnalyzerSQL injection in FortiManager, FortiAnalyzer and othersMEDIUM 6.50.51%–
CVE-2026-22828FortiManager and FortiAnalyzerHeap-based buffer overflow in FortiAnalyzer Cloud, FortiManager CloudHIGH 7.30.90%–
CVE-2026-39815Other security productsSQL injection in FortiDDoS-FHIGH 7.90.51%–
CVE-2026-22573Other security productsPath traversal in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 6.20.42%–
CVE-2025-61886FortiSandboxCross-site scripting in FortiSandbox PaaS, FortiSandboxMEDIUM 4.90.27%–
CVE-2026-39810FortiClient and EMSUse of hard-coded cryptographic key in FortiClientEMSMEDIUM 5.20.15%–
CVE-2026-39811FortiWebInteger overflow or wraparound in FortiWebMEDIUM 4.40.44%–
CVE-2024-23104Other security productsExposure of sensitive information to an unauthorized actor in FortiVoice, FortiNDRMEDIUM 5.40.26%–
CVE-2026-39812FortiSandboxCross-site scripting in FortiSandbox, FortiSandbox PaaSMEDIUM 4.30.24%–
CVE-2026-23708Other security productsImproper authentication in FortiSOAR PaaS, FortiSOAR on-premiseMEDIUM 6.70.28%–
CVE-2026-39814FortiWebRelative path traversal in FortiWebMEDIUM 6.20.19%–
CVE-2026-25691FortiSandboxPath traversal in FortiSandbox PaaS, FortiSandbox Cloud and othersMEDIUM 6.20.47%–
CVE-2025-59809Other security productsServer-side request forgery (ssrf) in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 4.10.20%–
CVE-2026-22155Other security productsCleartext transmission of sensitive information in FortiSOAR PaaS, FortiSOAR on-premiseMEDIUM 6.20.17%–
CVE-2026-21742Other security productsCleartext transmission of sensitive information in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 5.40.15%–
CVE-2026-22574Other security productsStoring passwords in a recoverable format in FortiSOAR PaaS, FortiSOAR on-premiseMEDIUM 4.10.27%–
CVE-2026-22154Other security productsCross-site scripting in FortiSOAR PaaS, FortiSOAR on-premiseMEDIUM 4.40.22%–
CVE-2025-53847FortiOSMissing authentication for critical function in FortiOSMEDIUM 6.20.28%–
CVE-2026-22576Other security productsStoring passwords in a recoverable format in FortiSOAR PaaS, FortiSOAR on-premiseMEDIUM 4.10.26%–
CVE-2026-27316FortiSandboxInsufficiently protected credentials in FortiSandbox, FortiSandbox PaaSLOW 2.50.30%–
CVE-2026-39808FortiSandboxFortiSandbox OS Command InjectionCRITICAL 9.147%Yes
CVE-2026-39809FortiClient and EMSSQL injection in FortiClientEMSMEDIUM 6.20.20%–
CVE-2026-35616FortiClient and EMSFortiClient EMS Improper Access ControlCRITICAL 9.19.1%Yes
CVE-2025-66178FortiWebOS command injection in FortiWebMEDIUM 6.71.7%–
CVE-2026-24641FortiWebNULL Pointer Dereference in FortiWebLOW 2.50.40%–
CVE-2026-24640FortiWebStack-based Buffer Overflow in FortiWebMEDIUM 5.90.66%–
CVE-2025-54659Other security productsPath traversal in FortiSOAR Agent Communication BridgeMEDIUM 5.50.48%–
CVE-2026-24017FortiWebImproper Control of Interaction Frequency in FortiWebHIGH 7.30.79%–
CVE-2026-25972FortiSIEMCross-site scripting in FortiSIEMMEDIUM 4.10.34%–
CVE-2026-22629FortiManager and FortiAnalyzerImproper restriction of excessive authentication attempts in FortiAnalyzer, FortiManager Cloud and othersLOW 3.40.38%–
CVE-2025-68482FortiManager and FortiAnalyzerImproper certificate validation in FortiAnalyzer, FortiManager and othersMEDIUM 6.30.19%–
CVE-2025-48418FortiManager and FortiAnalyzerHidden functionality in FortiAnalyzer, FortiAnalyzer Cloud and othersMEDIUM 6.40.54%–
CVE-2025-49784FortiManager and FortiAnalyzerSQL injection in FortiAnalyzer-BigData, FortiAnalyzerMEDIUM 5.60.46%–
CVE-2026-22572FortiManager and FortiAnalyzerAuthentication bypass using an alternate path or channel in FortiManager, FortiAnalyzerMEDIUM 6.80.58%–
CVE-2025-68648FortiManager and FortiAnalyzerUse of externally-controlled format string in FortiManager Cloud, FortiAnalyzer Cloud and othersMEDIUM 6.50.59%–
CVE-2026-25689Other security productsArgument injection in FortiDeceptorMEDIUM 60.60%–
CVE-2025-53608FortiSandboxCross-site scripting in FortiSandboxMEDIUM 4.60.32%–
CVE-2026-24018FortiClient and EMSUNIX symbolic link (Symlink) following in FortiClientLinuxHIGH 7.40.24%–
CVE-2025-48840FortiWebAuthentication bypass by spoofing in FortiWebMEDIUM 50.48%–
CVE-2025-54820FortiManager and FortiAnalyzerStack-based Buffer Overflow in FortiManagerHIGH 70.89%–
CVE-2025-55717FortiMailCleartext storage of sensitive information in FortiVoice, FortiMail and othersLOW 3.80.08%–
CVE-2026-25836FortiSandboxOS command injection in FortiSandbox Cloud, FortiSandbox PaaSMEDIUM 6.71.6%–
CVE-2026-30897FortiWebStack-based buffer overflow in FortiWebMEDIUM 5.90.70%–
CVE-2025-62439FortiOSImproper Verification of Source of a Communication Channel in FortiOSLOW 3.80.16%–
CVE-2025-62676FortiClient and EMSLink following in FortiClientWindowsMEDIUM 6.40.24%–
CVE-2025-68686FortiOSFortiOS Exposure of Sensitive Information to an Unauthorized ActorMEDIUM 5.329%Yes
CVE-2025-64157FortiOSUse of externally-controlled format string in FortiOSMEDIUM 6.71.5%–
CVE-2025-55018FortiOSHTTP request smuggling in FortiOSMEDIUM 5.20.40%–
CVE-2026-22153FortiOSAuthentication Bypass by Primary Weakness in FortiOSHIGH 7.50.76%–
CVE-2026-21743Other security productsMissing authorization in FortiAuthenticatorMEDIUM 6.80.38%–
CVE-2025-52436FortiSandboxCross-site scripting in FortiSandboxHIGH 7.97.3%–
CVE-2026-21643FortiClient and EMSFortiClient EMS SQL InjectionCRITICAL 9.194%Yes
CVE-2026-24858Full analysisFortiOSAuthentication Bypass Using an Alternate Path or Channel in FortiOS, FortiProxy and othersCRITICAL 9.486%Yes
CVE-2025-25249Full analysisFortiOSHeap-based buffer overflow in FortiOS, FortiSwitchManagerHIGH 7.43.8%Yes
CVE-2025-67685FortiSandboxServer-Side Request Forgery (SSRF) in FortiSandboxLOW 3.40.42%–
CVE-2025-58693Other security productsPath traversal in FortiVoiceMEDIUM 5.70.67%–
CVE-2025-59922FortiClient and EMSSQL injection in FortiClientEMSMEDIUM 6.87.8%–
CVE-2025-64155FortiSIEMOS command injection in FortiSIEMCRITICAL 9.443%–
CVE-2024-40593FortiOSKey management errors in FortiAnalyzer, FortiPortal and othersMEDIUM 5.90.11%–
CVE-2024-47570FortiOSInsertion of sensitive information into log file in FortiSASE, FortiProxy and othersMEDIUM 6.30.40%–
CVE-2025-59718FortiOSImproper verification of cryptographic signature in FortiOS, FortiProxy and othersCRITICAL 9.168%Yes
CVE-2025-59719FortiWebImproper verification of cryptographic signature in FortiWebCRITICAL 9.129%–
CVE-2025-53679FortiSandboxOS command injection in FortiSandbox, FortiSandbox CloudMEDIUM 6.912%–
CVE-2025-54353FortiSandboxCross-site scripting in FortiSandboxMEDIUM 5.36.3%–
CVE-2025-53949FortiSandboxOS command injection in FortiSandboxHIGH 717%–
CVE-2025-59810Other security productsImproper access control in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 6.20.26%–
CVE-2025-59808Other security productsUnverified password change in FortiSOAR on-premise, FortiSOAR PaaSMEDIUM 6.50.23%–
CVE-2025-54838FortiManager and FortiAnalyzerIncorrect Authorization in FortiPortalMEDIUM 6.40.31%–
CVE-2025-62631FortiOSInsufficient session expiration in FortiOSMEDIUM 5.30.30%–
CVE-2025-57823Other security productsForced browsing in FortiAuthenticatorLOW 2.60.23%–
CVE-2025-64153Other security productsOS command injection in FortiExtenderMEDIUM 6.71.7%–
CVE-2025-59923Other security productsImproper access control in FortiAuthenticatorLOW 2.60.21%–
CVE-2025-64156Other security productsSQL injection in FortiVoiceMEDIUM 6.80.32%–
CVE-2025-64471FortiWebUse of password hash instead of password for authentication in FortiWebMEDIUM 4.40.34%–
CVE-2025-60024Other security productsPath traversal in FortiVoiceHIGH 7.70.46%–
CVE-2025-64447FortiWebReliance on cookies without validation and integrity checking in FortiWebHIGH 7.18.4%–
CVE-2025-58412Other security productsImproper neutralization of script-related html tags in a web page (basic xss) in FortiADCMEDIUM 4.20.17%–
CVE-2025-53843FortiOSStack-based buffer overflow in FortiOSMEDIUM 6.90.59%–
CVE-2025-48839Other security productsOut-of-bounds Write in FortiADCMEDIUM 6.30.36%–
CVE-2025-54821FortiOSImproper Privilege Management in FortiPAM, FortiSASE and othersLOW 1.80.15%–
CVE-2025-58413FortiOSStack-based buffer overflow in FortiOS, FortiSASEMEDIUM 6.90.32%–
CVE-2025-46215FortiSandboxImproper Isolation or Compartmentalization in FortiSandboxMEDIUM 50.32%–
CVE-2025-59669FortiWebUse of hard-coded credentials in FortiWebMEDIUM 4.80.12%–
CVE-2025-54660FortiClient and EMSActive debug code in FortiClientWindowsMEDIUM 4.90.15%–
CVE-2025-61713Other security productsCleartext Storage of Sensitive Information in Memory in FortiPAMLOW 3.80.11%–
CVE-2025-46776Other security productsClassic buffer overflow in FortiExtenderMEDIUM 6.30.15%–
CVE-2025-46775Other security productsDebug messages revealing unnecessary information in FortiExtenderMEDIUM 5.20.16%–
CVE-2025-54971Other security productsExposure of sensitive information to an unauthorized actor in FortiADCLOW 3.90.23%–
CVE-2025-54972FortiMailCrlf injection in FortiMailLOW 3.90.20%–
CVE-2025-46373FortiClient and EMSHeap-based Buffer Overflow in FortiClientWindowsHIGH 7.10.15%–
CVE-2025-58692Other security productsSQL injection in FortiVoiceHIGH 7.70.32%–
CVE-2025-58034FortiWebFortiWeb OS Command InjectionMEDIUM 6.756%Yes
CVE-2025-47761FortiClient and EMSExposed IOCTL with Insufficient Access Control in FortiClientWindowsHIGH 7.10.16%–
CVE-2025-64446Full analysisFortiWebFortiWeb Path TraversalCRITICAL 9.492%Yes
CVE-2025-46752Other security productsInsertion of sensitive information into log file in FortiDLPMEDIUM 4.20.16%–
CVE-2025-53950Other security productsPrivacy violation in FortiDLPMEDIUM 5.10.18%–
CVE-2025-53951Other security productsPath traversal in FortiDLPMEDIUM 4.90.21%–
CVE-2025-54658Other security productsPath traversal in FortiDLPHIGH 7.20.21%–
CVE-2025-31514FortiOSInsertion of sensitive information into log file in FortiOS, FortiProxyLOW 2.60.36%–
CVE-2025-46774FortiClient and EMSImproper Verification of Cryptographic Signature in FortiClientMacMEDIUM 6.80.08%–
CVE-2025-54822FortiOSImproper authorization in FortiProxy, FortiOSMEDIUM 4.20.32%–
CVE-2025-31365FortiClient and EMSCode injection in FortiClientMacMEDIUM 5.50.28%–
CVE-2025-53845FortiManager and FortiAnalyzerImproper authentication in FortiAnalyzerMEDIUM 6.20.46%–
CVE-2025-59921Other security productsExposure of sensitive information to an unauthorized actor in FortiADCMEDIUM 6.20.30%–
CVE-2024-33507Other security productsInsufficient session expiration in FortiIsolatorHIGH 70.39%–
CVE-2025-57716FortiClient and EMSUncontrolled Search Path Element in FortiClientWindowsMEDIUM 60.18%–
CVE-2025-25255FortiOSImproperly Implemented Security Check for Standard in FortiOS, FortiProxyMEDIUM 4.80.43%–
CVE-2025-25252FortiOSInsufficient Session Expiration in FortiOSMEDIUM 4.30.34%–
CVE-2024-26008FortiOSImproper check or handling of exceptional conditions in FortiProxy, FortiPAM and othersMEDIUM 50.47%–
CVE-2024-47569FortiOSInsertion of sensitive information into sent data in FortiManager Cloud, FortiTester and othersMEDIUM 4.20.47%–
CVE-2025-54973FortiManager and FortiAnalyzerRace condition in FortiAnalyzerMEDIUM 5.30.32%–
CVE-2023-46718FortiOSStack-based buffer overflow in FortiOS, FortiProxyMEDIUM 6.30.19%–
CVE-2024-50571FortiOSHeap-based buffer overflow in FortiManager, FortiOS and othersMEDIUM 6.50.54%–
CVE-2025-31366FortiOSImproper Neutralization of Input During Web Page Generation in FortiSASE, FortiOS and othersMEDIUM 4.50.40%–
CVE-2025-22258FortiOSHeap-based buffer overflow in FortiPAM, FortiOS and othersMEDIUM 5.70.56%–
CVE-2025-25253FortiOSImproper Validation of Certificate with Host Mismatch in FortiProxy, FortiOS and othersMEDIUM 6.80.11%–
CVE-2025-57740FortiOSHeap-based Buffer Overflow in FortiPAM, FortiProxy and othersMEDIUM 6.70.68%–
CVE-2025-47890FortiOSURL Redirection to Untrusted Site in FortiOS, FortiProxy and othersLOW 2.50.25%–
CVE-2025-57741FortiClient and EMSIncorrect Permission Assignment for Critical Resource in FortiClientMacHIGH 70.13%–
CVE-2025-49201Other security productsWeak authentication in FortiPAM, FortiSwitchManagerHIGH 7.40.58%–
CVE-2025-58325FortiOSIncorrect Provision of Specified Functionality in FortiOSHIGH 7.80.29%–
CVE-2025-58324FortiSIEMImproper neutralization of input during web page generation in FortiSIEMMEDIUM 6.10.27%–
CVE-2025-58903FortiOSUnchecked Return Value in FortiOSLOW 2.50.62%–
CVE-2024-48891Other security productsOS command injection in FortiSOAR on-premiseMEDIUM 6.60.45%–
CVE-2025-47856Other security productsOS command injection in FortiVoiceHIGH 7.21.3%–
CVE-2025-22862FortiOSAuthentication Bypass Using an Alternate Path or Channel in FortiProxy, FortiOSMEDIUM 6.30.25%–
CVE-2024-45325Other security productsOS command injection in FortiDDoS-FMEDIUM 6.50.47%–
CVE-2025-53609FortiWebRelative Path Traversal in FortiWebMEDIUM 4.79.3%–
CVE-2024-48892Other security productsRelative path traversal in FortiSOARMEDIUM 6.40.40%–
CVE-2025-47857FortiWebOS command injection in FortiWebMEDIUM 6.50.48%–
CVE-2025-32932Other security productsCross-site scripting in FortiSOARMEDIUM 6.20.20%–
CVE-2025-27759FortiWebOS command injection in FortiWebMEDIUM 6.70.45%–
CVE-2024-26009FortiOSAuthentication bypass using an alternate path or channel in FortiProxy, FortiOS and othersHIGH 7.90.59%–
CVE-2024-52964FortiManager and FortiAnalyzerPath traversal in FortiManagerMEDIUM 5.20.63%–
CVE-2025-25248FortiOSInteger Overflow or Wraparound in FortiOS, FortiPAM and othersMEDIUM 4.80.48%–
CVE-2023-45584FortiOSDouble free in FortiProxy, FortiOS and othersMEDIUM 6.30.59%–
CVE-2025-52970FortiWebImproper handling of parameters in FortiWebHIGH 7.710%–
CVE-2025-53744FortiOSIncorrect privilege assignment in FortiOSMEDIUM 6.80.64%–
CVE-2025-49813Other security productsOS command injection in FortiADCMEDIUM 6.61.1%–
CVE-2025-32766FortiWebStack-based buffer overflow in FortiWebMEDIUM 6.30.14%–
CVE-2025-25256FortiSIEMOS command injection in FortiSIEMCRITICAL 9.865%–
CVE-2024-40588FortiMailMultiple relative path traversal in FortiCamera, FortiNDR and othersMEDIUM 4.20.18%–
CVE-2024-32124Other security productsImproper access control in FortiIsolatorMEDIUM 40.36%–
CVE-2024-27779FortiSandboxInsufficient session expiration in FortiSandbox, FortiIsolatorMEDIUM 6.30.52%–
CVE-2025-25257FortiWebFortiWeb SQL InjectionCRITICAL 9.6100%Yes
CVE-2025-24477FortiOSHeap-based buffer overflow in FortiOSMEDIUM 40.22%–
CVE-2024-52965FortiOSMissing critical step in authentication in FortiOS, FortiProxyMEDIUM 6.80.30%–
CVE-2025-24474FortiManager and FortiAnalyzerSQL injection in FortiManager, FortiAnalyzerLOW 2.60.31%–
CVE-2024-55599FortiOSImproperly Implemented Security Check for Standard in FortiOS, FortiProxyMEDIUM 4.90.40%–
CVE-2024-50568FortiOSChannel accessible by non-endpoint in FortiOS, FortiProxyMEDIUM 5.60.45%–
CVE-2025-25250FortiOSExposure of Sensitive Information to an Unauthorized Actor in FortiOS, FortiSASELOW 3.90.54%–
CVE-2023-29184FortiOSIncomplete cleanup in FortiProxy, FortiOSLOW 3.10.21%–
CVE-2023-48786FortiClient and EMSServer-side request forgery in FortiClientEMSMEDIUM 4.10.34%–
CVE-2025-24471FortiOSImproper Certificate Validation in FortiOSMEDIUM 60.38%–
CVE-2025-22254FortiOSImproper Privilege Management in FortiOS, FortiProxy and othersMEDIUM 6.50.85%–
CVE-2025-22256Other security productsImproper handling of insufficient permissions or privileges in FortiPAM, FortiSRAMEDIUM 60.37%–
CVE-2024-32119FortiClient and EMSImproper authentication in FortiClientEMSMEDIUM 4.60.33%–
CVE-2025-31104Other security productsOS command injection in FortiADCHIGH 71.1%–
CVE-2025-22251FortiOSImproper restriction of communication channel to intended endpoints in FortiOSLOW 30.40%–
CVE-2024-50562FortiOSInsufficient Session Expiration in FortiOS, FortiPAM and othersMEDIUM 4.41.2%–
CVE-2024-54019FortiClient and EMSImproper validation of certificate with host mismatch in FortiClientWindowsMEDIUM 4.40.17%–
CVE-2024-45329FortiManager and FortiAnalyzerAuthorization bypass through user-controlled key in FortiPortalLOW 3.90.32%–
CVE-2025-46777FortiManager and FortiAnalyzerInsertion of sensitive information into log file in FortiPortalLOW 2.20.24%–
CVE-2025-24473FortiClient and EMSExposure of sensitive system information to an unauthorized control sphere in FortiClientWindowsMEDIUM 4.80.55%–
CVE-2025-22252FortiOSMissing authentication for critical function in FortiProxy, FortiSwitchManager and othersCRITICAL 90.94%–
CVE-2025-47294FortiOSInteger overflow or wraparound in FortiOSMEDIUM 4.80.84%–
CVE-2024-54020FortiManager and FortiAnalyzerMissing authorization in FortiManagerLOW 2.10.20%–
CVE-2025-47295FortiOSBuffer over-read in FortiOSLOW 3.40.78%–
CVE-2025-25251FortiClient and EMSIncorrect Authorization in FortiClientMacHIGH 7.40.19%–
CVE-2025-32756FortiMailStack-based buffer overflow in FortiMail, FortiVoice and othersCRITICAL 9.631%Yes
CVE-2025-22859FortiClient and EMSRelative Path Traversal in FortiClientEMSMEDIUM 50.60%–
CVE-2024-35281FortiClient and EMSImproper isolation or compartmentalization in FortiClientMac, FortiVoiceUCDesktopLOW 2.30.14%–
CVE-2024-48887Other security productsUnverified password change in FortiSwitchCRITICAL 9.316%–
CVE-2024-50565FortiOSImproper restriction of communication channel to intended endpoints in FortiOS, FortiVoice and othersLOW 30.40%–
CVE-2024-26013FortiOSImproper restriction of communication channel to intended endpoints in FortiProxy, FortiManager and othersHIGH 7.10.51%–
CVE-2023-37930FortiOSMultiple issues including the use of uninitialized ressources in FortiProxy, FortiOSMEDIUM 6.70.64%–
CVE-2024-52962FortiManager and FortiAnalyzerImproper Output Neutralization for Logs in FortiAnalyzer, FortiManagerMEDIUM 50.51%–
CVE-2024-46671FortiWebIncorrect User Management in FortiWebMEDIUM 5.60.45%–
CVE-2024-32122FortiOSStoring passwords in a recoverable format in FortiOSLOW 2.10.22%–
CVE-2024-54024Other security productsOS command injection in FortiIsolatorHIGH 71.2%–
CVE-2024-54025Other security productsOS command injection in FortiIsolatorMEDIUM 6.50.45%–
CVE-2025-25254FortiWebPath traversal in FortiWebMEDIUM 6.817%–
CVE-2025-22855FortiClient and EMSCross-site scripting in FortiClientEMSLOW 2.60.36%–
CVE-2023-40714FortiSIEMRelative path traversal in FortiSIEMCRITICAL 9.70.62%–
CVE-2023-33302FortiMailClassic buffer overflow in FortiNDR, FortiMailMEDIUM 4.50.37%–
CVE-2021-24008Other security productsExposure of sensitive system information to an unauthorized control sphere in FortiDDoS, FortiNDR and othersMEDIUM 50.50%–
CVE-2019-16149FortiClient and EMSAn Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a…MEDIUM 5.40.29%–
CVE-2023-25610FortiOSBuffer underflow in FortiSwitchManager, FortiAnalyzer and othersCRITICAL 9.318%–
CVE-2021-26091FortiMailUse of a cryptographically weak pseudo-random number generator in FortiMailMEDIUM 6.90.31%–
CVE-2021-26105FortiSandboxStack-based buffer overflow in FortiSandboxMEDIUM 6.40.50%–
CVE-2019-16151FortiOSImproper neutralization of input during web page generation in FortiOSMEDIUM 4.70.37%–
CVE-2023-47539FortiMailImproper access control in FortiMailCRITICAL 91.0%–
CVE-2024-21760Other security productsCode injection in FortiSOARHIGH 7.70.81%–
CVE-2019-6697FortiOSImproper Neutralization of Input in FortiOSMEDIUM 5.20.35%–
CVE-2020-9295FortiClient and EMSFortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and…MEDIUM 4.70.32%–
CVE-2020-29010FortiOSExposure of sensitive information to an unauthorized actor in FortiOSMEDIUM 4.90.57%–
CVE-2019-17659FortiSIEMUse of hard-coded cryptographic key in FortiSIEMLOW 3.60.65%–
CVE-2024-54027FortiSandboxUse of Hard-coded Cryptographic Key in FortiSandboxHIGH 7.80.16%–
CVE-2019-15706FortiOSAn improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version…MEDIUM 40.43%–
CVE-2024-55594FortiWebImproper handling of syntactically invalid structure in FortiWebMEDIUM 5.50.53%–
CVE-2023-48785FortiNACImproper certificate validation in FortiNAC-FMEDIUM 4.40.17%–
CVE-2023-33300FortiNACCommand injection in FortiNACMEDIUM 4.814%–
CVE-2023-45588FortiClient and EMSExternal control of file name or path in FortiClientMacHIGH 7.80.27%–
CVE-2024-40585FortiManager and FortiAnalyzerInsertion of sensitive information into log file in FortiAnalyzer, FortiManagerMEDIUM 5.90.31%–
CVE-2022-29059FortiWebSQL injection in FortiWebLOW 2.60.41%–
CVE-2024-47573Other security productsImproper validation of integrity check value in FortiNDRMEDIUM 60.22%–
CVE-2024-46662FortiManager and FortiAnalyzerCommand injection in FortiManagerHIGH 8.32.3%–
CVE-2024-40590FortiManager and FortiAnalyzerImproper certificate validation in FortiPortalMEDIUM 4.40.16%–
CVE-2024-26006FortiOSImproper neutralization of input during web page Generation in FortiProxy, FortiOSMEDIUM 6.90.61%–
CVE-2024-33501FortiManager and FortiAnalyzerSQL injection in FortiManagerMEDIUM 40.18%–
CVE-2024-54026FortiSandboxSQL injection in FortiSandbox, FortiSandbox CloudMEDIUM 4.10.42%–
CVE-2024-32123FortiManager and FortiAnalyzerOS command injection in FortiManager, FortiAnalyzerMEDIUM 6.50.44%–
CVE-2024-54018FortiSandboxMultiple improper neutralization of special elements used in an OS Command in FortiSandboxMEDIUM 6.510%–
CVE-2023-37933Other security productsCross-site scripting in FortiADCHIGH 8.60.33%–
CVE-2024-52960FortiSandboxClient-side enforcement of server-side security in FortiSandboxMEDIUM 4.20.34%–
CVE-2024-55590Other security productsOS command injection in FortiIsolatorHIGH 8.61.0%–
CVE-2024-45324FortiOSUse of externally-controlled format string in FortiPAM, FortiWeb and othersHIGH 70.73%–
CVE-2024-46663FortiMailStack-buffer overflow in FortiMailMEDIUM 6.50.18%–
CVE-2023-48790Other security productsCross site request forgery in FortiNDRHIGH 7.10.24%–
CVE-2024-52961FortiSandboxImproper neutralization of special elements used in an OS Command in FortiSandboxHIGH 8.60.55%–
CVE-2024-55592FortiSIEMIncorrect authorization in FortiSIEMLOW 3.60.26%–
CVE-2023-42784FortiWebImproper handling of syntactically invalid structure in FortiWebMEDIUM 5.50.38%–
CVE-2024-45328FortiSandboxIncorrect authorization in FortiSandboxHIGH 7.10.14%–
CVE-2023-40723FortiSIEMExposure of sensitive information to an unauthorized actor in FortiSIEMHIGH 7.70.36%–
CVE-2024-55597FortiWebPath traversal in FortiWebMEDIUM 5.20.58%–
CVE-2025-24472FortiOSFortiOS and FortiProxy Authentication BypassHIGH 8.17.2%Yes · ransomware
CVE-2024-27780FortiSIEMCross-site scripting in FortiSIEMLOW 2.20.30%–
CVE-2024-27781FortiSandboxCross-site scripting in FortiSandboxMEDIUM 6.928%–
CVE-2024-40584FortiManager and FortiAnalyzerOS command injection in FortiAnalyzer, FortiManagerMEDIUM 6.82.0%–
CVE-2024-36508FortiManager and FortiAnalyzerPath traversal in FortiManager, FortiAnalyzerMEDIUM 5.90.24%–
CVE-2024-40586FortiClient and EMSImproper Access Control in FortiClientWindowsMEDIUM 6.30.25%–
CVE-2023-40721FortiOSUse of externally-controlled format string in FortiPAM, FortiSwitchManager and othersMEDIUM 6.30.24%–
CVE-2024-50567FortiWebOS command injection in FortiWebMEDIUM 6.82.2%–
CVE-2024-33504FortiManager and FortiAnalyzerUse of hard-coded cryptographic key to encrypt sensitive data in FortiManagerLOW 3.90.30%–
CVE-2024-35279FortiOSStack-based buffer overflow in FortiOSHIGH 7.71.0%–
CVE-2024-40591FortiOSIncorrect privilege assignment in FortiOSHIGH 80.62%–
CVE-2024-52966FortiManager and FortiAnalyzerExposure of sensitive information to an unauthorized actor in FortiAnalyzerLOW 2.20.21%–
CVE-2024-52968FortiClient and EMSImproper authentication in FortiClientMacMEDIUM 5.80.24%–
CVE-2024-50569FortiWebOS command injection in FortiWebMEDIUM 6.31.8%–
CVE-2025-24470FortiManager and FortiAnalyzerImproper Resolution of Path Equivalence in FortiPortalHIGH 8.11.3%–
CVE-2022-23439FortiOSExternally controlled reference to a resource in another sphere in FortiTester, FortiOS and othersMEDIUM 4.10.45%–
CVE-2024-50563FortiManager and FortiAnalyzerWeak authentication in FortiAnalyzer, FortiManagerMEDIUM 6.70.58%–
CVE-2024-48885FortiWebPath traversal in FortiVoice, FortiRecorder and othersMEDIUM 5.20.79%–
CVE-2024-45331FortiManager and FortiAnalyzerIncorrect privilege assignment in FortiAnalyzer Cloud, FortiManager and othersMEDIUM 6.90.21%–
CVE-2024-35280Other security productsCross-site scripting in FortiDeceptorMEDIUM 5.10.29%–
CVE-2024-32115FortiManager and FortiAnalyzerRelative path traversal in FortiManagerMEDIUM 5.21.1%–
CVE-2024-23106FortiClient and EMSImproper restriction of excessive authentication attempts in FortiClientEMSHIGH 7.70.96%–
CVE-2023-37931Other security productsSQL injection in FortiVoiceHIGH 8.60.80%–
CVE-2024-47571FortiManager and FortiAnalyzerOperation on a resource after expiration or release in FortiManagerHIGH 7.90.91%–
CVE-2024-47572Other security productsImproper neutralization of formula elements in a csv file in FortiSOARHIGH 8.30.58%–
CVE-2024-46667FortiSIEMAllocation of resources without limits or throttling in FortiSIEMMEDIUM 6.90.59%–
CVE-2024-36504FortiOSOut-of-bounds read in FortiOSMEDIUM 6.20.72%–
CVE-2024-21758FortiWebStack-based buffer overflow in FortiWebMEDIUM 6.10.22%–
CVE-2024-46666FortiOSAllocation of resources without limits or throttling in FortiOSMEDIUM 4.80.69%–
CVE-2024-45326Other security productsImproper Access Control in FortiDeceptorLOW 3.90.26%–
CVE-2024-35277FortiManager and FortiAnalyzerMissing authentication for critical function in FortiManagerHIGH 8.40.71%–
CVE-2024-26012Other security productsOS command injection in FortiAP-S, FortiAP-W2 and othersMEDIUM 6.30.69%–
CVE-2024-36506FortiClient and EMSImproper verification of source of a communication channel in FortiClientEMSLOW 3.50.51%–
CVE-2024-48890Other security productsOS command injection in FortiSOARMEDIUM 6.31.1%–
CVE-2024-33502FortiManager and FortiAnalyzerPath traversal in FortiManager, FortiAnalyzerMEDIUM 6.41.3%–
CVE-2024-50564FortiClient and EMSUse of hard-coded cryptographic key in FortiClientWindowsLOW 3.20.22%–
CVE-2024-36510FortiClient and EMSObservable response discrepancy in FortiClientEMS, FortiSOARMEDIUM 4.90.73%–
CVE-2024-54021FortiOSHTTP response splitting in FortiOS, FortiProxyMEDIUM 6.40.78%–
CVE-2024-35278FortiManager and FortiAnalyzerSQL injection in FortiPortalMEDIUM 4.10.37%–
CVE-2024-52967FortiManager and FortiAnalyzerImproper neutralization of script-related html tags in a web page (basic xss) in FortiPortalLOW 3.30.36%–
CVE-2024-40587Other security productsOS command injection in FortiVoiceMEDIUM 6.30.63%–
CVE-2024-46664Other security productsRelative path traversal in FortiRecorderMEDIUM 5.20.53%–
CVE-2024-47566Other security productsPath traversal in FortiRecorderMEDIUM 4.80.20%–
CVE-2024-48886FortiOSWeak authentication in FortiOS, FortiProxyHIGH 80.48%–
CVE-2024-27778FortiSandboxImproper neutralization of special elements used in an OS Command in FortiSandboxHIGH 8.30.56%–
CVE-2024-33503FortiManager and FortiAnalyzerImproper privilege management in FortiManager Cloud, FortiManagerMEDIUM 6.70.22%–
CVE-2023-37936Other security productsUse of hard-coded cryptographic key in FortiSwitchCRITICAL 9.60.99%–
CVE-2023-37937Other security productsOS command injection in FortiSwitchHIGH 7.60.53%–
CVE-2024-56497FortiMailOS command injection in FortiMail, FortiRecorderMEDIUM 6.50.59%–
CVE-2024-48884FortiOSPath traversal in FortiManager, FortiProxy and othersHIGH 7.115%–
CVE-2024-52969FortiSIEMSQL injection in FortiSIEMLOW 3.70.50%–
CVE-2024-46668FortiOSAllocation of resources without limits or throttling in FortiOSHIGH 7.11.00%–
CVE-2024-35273FortiManager and FortiAnalyzerOut-of-bounds write in FortiAnalyzer, FortiManagerHIGH 70.66%–
CVE-2023-46715FortiOSOrigin validation error in FortiProxy, FortiOSMEDIUM 4.70.95%–
CVE-2023-42786FortiOSA null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions,…MEDIUM 6.40.87%–
CVE-2024-35276FortiManager and FortiAnalyzerStack-based buffer overflow in FortiAnalyzer, FortiManager Cloud and othersMEDIUM 50.42%–
CVE-2024-35275FortiManager and FortiAnalyzerSQL injection in FortiManager, FortiAnalyzerMEDIUM 6.50.82%–
CVE-2023-42785FortiOSA null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions,…MEDIUM 6.40.71%–
CVE-2024-36512FortiManager and FortiAnalyzerPath traversal in FortiManager, FortiAnalyzerHIGH 71.4%–
CVE-2024-46670FortiOSOut-of-bounds Read in FortiOS, FortiProxy and othersHIGH 7.50.63%–
CVE-2024-46669FortiOSInteger Overflow or Wraparound in FortiOSLOW 3.20.60%–
CVE-2024-55593FortiWebSQL injection in FortiWebLOW 2.60.41%–
CVE-2024-50566FortiManager and FortiAnalyzerOS command injection in FortiManager, FortiManager CloudHIGH 7.21.1%–
CVE-2024-55591FortiOSFortiOS and FortiProxy Authentication BypassCRITICAL 9.694%Yes · ransomware
CVE-2024-52963FortiOSOut-of-bounds write in FortiProxy, FortiOS and othersLOW 3.50.76%–
CVE-2024-48893Other security productsImproper neutralization of input during web page generation in FortiSOARMEDIUM 6.40.46%–
CVE-2024-46665FortiOSInsertion of sensitive information into sent data in FortiOSLOW 3.50.54%–
CVE-2024-47575FortiManager and FortiAnalyzerFortiManager Missing AuthenticationCRITICAL 9.895%Yes
CVE-2023-48788FortiClient and EMSFortiClient EMS SQL InjectionCRITICAL 9.398%Yes · ransomware
CVE-2024-23113FortiOSUse of externally-controlled format string in FortiOS, FortiProxy and othersCRITICAL 9.862%Yes
CVE-2024-21762FortiOSFortiOS Out-of-Bound WriteCRITICAL 9.683%Yes · ransomware
CVE-2023-27997FortiOSFortiOS and FortiProxy SSL-VPN Heap-Based Buffer OverflowCRITICAL 9.286%Yes · ransomware
CVE-2022-41328FortiOSFortiOS Path TraversalMEDIUM 6.511%Yes
CVE-2022-42475FortiOSFortiOS Heap-Based Buffer OverflowCRITICAL 9.399%Yes · ransomware
CVE-2022-40684FortiOSAuthentication bypass using an alternate path or channel in Fortinet FortiOS, FortiProxy, FortiSwitchManagerCRITICAL 9.8100%Yes · ransomware
CVE-2021-44168FortiOSFortiOS Arbitrary File DownloadLOW 3.30.86%Yes
CVE-2019-5591FortiOSFortiOS Default ConfigurationMEDIUM 6.519%Yes · ransomware
CVE-2020-12812FortiOSFortiOS SSL VPN Improper AuthenticationHIGH 7.545%Yes · ransomware
CVE-2019-6693FortiOSFortiOS Use of Hard-Coded CredentialsMEDIUM 6.55.8%Yes · ransomware
CVE-2018-13382FortiOSFortiOS and FortiProxy Improper AuthorizationCRITICAL 9.182%Yes · ransomware
CVE-2018-13379FortiOSFortiOS SSL VPN Path TraversalCRITICAL 9.1100%Yes · ransomware
CVE-2018-13383FortiOSFortiOS and FortiProxy Out-of-bounds WriteMEDIUM 4.334%Yes · ransomware
CVE-2018-13374FortiOSFortiOS and FortiADC Improper Access ControlMEDIUM 4.338%Yes · ransomware

Sources: Fortinet security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.