Fortinet vendor intelligence
Fortinet Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Fortinet products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 34
- Known exploited vulnerabilities affecting Fortinet products
- In CISA KEV
- 29
- Records also listed in the official catalog
- Beyond CISA KEV
- 5
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 3
- Fortinet KEVs with sensor-observed exploitation activity
The catalog gap matters for Fortinet exposure
Five of the 34 exploited Fortinet CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 15% of this vendor portfolio.
- 85%
- Covered by CISA
- 15%
- Beyond CISA
- 23
- Product families
Attested Fortinet CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-68686
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,... |
FortiOS | Confirmed | In CISA | 27 Jul 2026 |
|
CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through... |
FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS | Confirmed | In CISA | 16 Jul 2026 |
|
CVE-2026-39813
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to... |
FortiSandbox, FortiSandbox Cloud | Confirmed | Beyond CISA | 15 Jun 2026 |
|
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through... |
FortiSandbox, FortiSandbox PaaS | Confirmed | In CISA | 12 Jun 2026 |
|
CVE-2021-22122
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an... |
Fortinet FortiWeb | High | Beyond CISA | 28 Dec 2025 |
|
CVE-2023-34993
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and... |
FortiWLM | High | Beyond CISA | 29 Jul 2025 |
|
CVE-2026-21643
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an... |
FortiClientEMS | Confirmed | In CISA | 28 May 2026 |
|
CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute... |
FortiClientEMS | Confirmed | In CISA | 28 May 2026 |
|
CVE-2026-25815
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from... |
FortiOS | High | Beyond CISA | 01 Jun 2026 |
|
CVE-2026-24858
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5,... |
FortiWeb, FortiNAC-F, FortiOS, FortiAnalyzer, FortiProxy, FortiManager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-59718
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS... |
FortiSwitchManager, FortiOS, FortiProxy | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-58034
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet... |
FortiWeb | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9,... |
FortiWeb | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions,... |
FortiNDR, FortiCamera, FortiRecorder, FortiVoice, FortiMail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-25257
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb... |
FortiWeb | Confirmed | In CISA | 28 May 2026 |
|
CVE-2019-6693
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup... |
FortiGate | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-39952
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0... |
FortiNAC | High | Beyond CISA | 23 Apr 2025 |
|
CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to... |
Fortinet FortiOS, FortiProxy | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-12812
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in... |
Fortinet FortiOS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-5591
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by... |
Fortinet FortiOS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-44168
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local... |
Fortinet FortiOS | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2018-13383
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy... |
Fortinet FortiOS and FortiProxy | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to... |
Fortinet FortiOS, FortiProxy | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2018-13374
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the... |
Fortinet FortiOS, fortiADC | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,... |
Fortinet FortiOS, FortiProxy, FortiSwitchManager | Confirmed | In CISA | 11 Oct 2022 |
|
CVE-2022-42475
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0... |
FortiProxy, FortiOS | Confirmed | In CISA | 13 Dec 2022 |
|
CVE-2022-41328
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through... |
FortiOS | Confirmed | In CISA | 14 Mar 2023 |
|
CVE-2023-27997
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,... |
FortiOS-6K7K, FortiProxy, FortiOS | Confirmed | In CISA | 13 Jun 2023 |
|
CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0... |
FortiProxy, FortiOS | Confirmed | In CISA | 09 Feb 2024 |
|
CVE-2023-48788
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2,... |
FortiClientEMS | Confirmed | In CISA | 25 Mar 2024 |
|
CVE-2024-23113
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,... |
FortiSwitchManager, FortiOS, FortiPAM, FortiProxy | Confirmed | In CISA | 09 Oct 2024 |
|
CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,... |
FortiManager | Confirmed | In CISA | 23 Oct 2024 |
|
CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy... |
FortiOS, FortiProxy | Confirmed | In CISA | 14 Jan 2025 |
|
CVE-2025-24472
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0... |
FortiOS, FortiProxy | Confirmed | In CISA | 18 Mar 2025 |
No Fortinet CVEs match this search or filter.
Showing 34 of 34 Fortinet known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and authentication bypass using an alternate path or channel account for ten mapped occurrences across this Fortinet KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-288
Authentication Bypass Using an Alternate Path or Channel
CWE-787
Out-of-bounds Write
CWE-306
Missing Authentication for Critical Function
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-287
Improper Authentication
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.