Fortinet vendor intelligence

Fortinet Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Fortinet products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
34
Known exploited vulnerabilities affecting Fortinet products
In CISA KEV
29
Records also listed in the official catalog
Beyond CISA KEV
5
Additional exploited CVEs absent from CISA KEV
Sensor Observed
3
Fortinet KEVs with sensor-observed exploitation activity

The catalog gap matters for Fortinet exposure

Five of the 34 exploited Fortinet CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 15% of this vendor portfolio.

85%
Covered by CISA
15%
Beyond CISA
23
Product families

Attested Fortinet CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2025-68686

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...

FortiOS Confirmed In CISA 27 Jul 2026
CVE-2026-25089

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through...

FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS Confirmed In CISA 16 Jul 2026
CVE-2026-39813

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to...

FortiSandbox, FortiSandbox Cloud Confirmed Beyond CISA 15 Jun 2026
CVE-2026-39808

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through...

FortiSandbox, FortiSandbox PaaS Confirmed In CISA 12 Jun 2026
CVE-2021-22122

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an...

Fortinet FortiWeb High Beyond CISA 28 Dec 2025
CVE-2023-34993

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and...

FortiWLM High Beyond CISA 29 Jul 2025
CVE-2026-21643

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an...

FortiClientEMS Confirmed In CISA 28 May 2026
CVE-2026-35616

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute...

FortiClientEMS Confirmed In CISA 28 May 2026
CVE-2026-25815

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from...

FortiOS High Beyond CISA 01 Jun 2026
CVE-2026-24858

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5,...

FortiWeb, FortiNAC-F, FortiOS, FortiAnalyzer, FortiProxy, FortiManager Confirmed In CISA 01 Jun 2026
CVE-2025-59718

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...

FortiSwitchManager, FortiOS, FortiProxy Confirmed In CISA 01 Jun 2026
CVE-2025-58034

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet...

FortiWeb Confirmed In CISA 01 Jun 2026
CVE-2025-64446

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9,...

FortiWeb Confirmed In CISA 01 Jun 2026
CVE-2025-32756

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions,...

FortiNDR, FortiCamera, FortiRecorder, FortiVoice, FortiMail Confirmed In CISA 01 Jun 2026
CVE-2025-25257

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb...

FortiWeb Confirmed In CISA 28 May 2026
CVE-2019-6693

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup...

FortiGate Confirmed In CISA 01 Jun 2026
CVE-2022-39952

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0...

FortiNAC High Beyond CISA 23 Apr 2025
CVE-2018-13379

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to...

Fortinet FortiOS, FortiProxy Confirmed In CISA 03 Nov 2021
CVE-2020-12812

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in...

Fortinet FortiOS Confirmed In CISA 03 Nov 2021
CVE-2019-5591

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by...

Fortinet FortiOS Confirmed In CISA 03 Nov 2021
CVE-2021-44168

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local...

Fortinet FortiOS Confirmed In CISA 10 Dec 2021
CVE-2018-13383

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy...

Fortinet FortiOS and FortiProxy Confirmed In CISA 10 Jan 2022
CVE-2018-13382

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to...

Fortinet FortiOS, FortiProxy Confirmed In CISA 10 Jan 2022
CVE-2018-13374

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the...

Fortinet FortiOS, fortiADC Confirmed In CISA 08 Sep 2022
CVE-2022-40684

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,...

Fortinet FortiOS, FortiProxy, FortiSwitchManager Confirmed In CISA 11 Oct 2022
CVE-2022-42475

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0...

FortiProxy, FortiOS Confirmed In CISA 13 Dec 2022
CVE-2022-41328

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through...

FortiOS Confirmed In CISA 14 Mar 2023
CVE-2023-27997

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,...

FortiOS-6K7K, FortiProxy, FortiOS Confirmed In CISA 13 Jun 2023
CVE-2024-21762

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0...

FortiProxy, FortiOS Confirmed In CISA 09 Feb 2024
CVE-2023-48788

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2,...

FortiClientEMS Confirmed In CISA 25 Mar 2024
CVE-2024-23113

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,...

FortiSwitchManager, FortiOS, FortiPAM, FortiProxy Confirmed In CISA 09 Oct 2024
CVE-2024-47575

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,...

FortiManager Confirmed In CISA 23 Oct 2024
CVE-2024-55591

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy...

FortiOS, FortiProxy Confirmed In CISA 14 Jan 2025
CVE-2025-24472

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0...

FortiOS, FortiProxy Confirmed In CISA 18 Mar 2025

Showing 34 of 34 Fortinet known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, neutralization, and authentication bypass using an alternate path or channel account for ten mapped occurrences across this Fortinet KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.