Netzwerksicherheit

Schwachstellen bei Fortinet: jede Meldung, die die Register seinen Produkten zuordnen

Kurz gesagt

110 Schwachstellenmeldungen in diesem Bestand sind Produkten von Fortinet zugeordnet. Sie reichen von November 2021 bis Juli 2026. 20 davon stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen. Jeder Eintrag unten verlinkt auf das Register, das ihn veröffentlicht hat.

Zugeordnet

110

an ein benanntes Produkt gebunden

Aktiv ausgenutzt

20

im CISA-Katalog geführt

Als kritisch eingestuft

26

Einstufung des Registers

Zuletzt geprüft

24. Juli 2026

Quellen neu abgefragt

Warum diese Liste kürzer ist als ein CVE-Spiegel

Die Register werden über Stichworte durchsucht, also liefert die Suche nach einem Firmennamen auch Meldungen zurück, die diesen Namen nur erwähnen. Ein Spiegel veröffentlicht sie mit. Diese Seite nicht: Ein Eintrag erscheint erst, wenn das Register selbst ihn an ein Produkt von Fortinet bindet, über einen Verweis auf eine Adresse des Anbieters, über Fortinet als die Stelle, die die CVE-Nummer vergeben hat, oder über die Liste der betroffenen Produkte.

0 Einträge haben diese Hürde nicht genommen und werden nicht angezeigt. Das ist der Unterschied, und er ist gewollt: Eine Seite, die die Schwachstelle eines anderen Unternehmens unter dieser Überschrift führt, ist auf die Art falsch, die am meisten kostet.

95 der 110 Einträge tragen einen CVSS-Basiswert aus dem Register. Wo keiner veröffentlicht ist, steht keiner, und geschätzt wird nichts.

Die vollständige Liste, bekannt ausgenutzte und neueste zuerst

Führen mehrere Register dieselbe Meldung, steht sie einmal da, mit einem Link auf jedes. So wird dieselbe Schwachstelle nicht doppelt gezählt. Einträge aus dem CISA-Katalog bekannt ausgenutzter Schwachstellen stehen oben, weil das der eine Hinweis auf dieser Seite ist, der ändert, was als Nächstes zu tun ist.

  • CVE-2026-39808criticalCVSS 9.1Aktiv ausgenutzt16. Juli 2026

    Fortinet FortiSandbox OS Command Injection Vulnerability

  • CVE-2026-25089criticalCVSS 9.1Aktiv ausgenutzt16. Juli 2026

    Fortinet FortiSandbox OS Command Injection Vulnerability

  • CVE-2026-21643criticalAktiv ausgenutzt13. Apr. 2026

    Fortinet FortiClient EMS SQL Injection Vulnerability

  • CVE-2026-35616criticalCVSS 9.1Aktiv ausgenutzt06. Apr. 2026

    Fortinet FortiClient EMS Improper Access Control Vulnerability

  • CVE-2026-24858criticalCVSS 9.4Aktiv ausgenutzt27. Jan. 2026

    Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • CVE-2025-59718criticalCVSS 9.1Aktiv ausgenutzt16. Dez. 2025

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

  • CVE-2025-58034criticalAktiv ausgenutzt18. Nov. 2025

    Fortinet FortiWeb OS Command Injection Vulnerability

  • CVE-2025-64446criticalAktiv ausgenutzt14. Nov. 2025

    Fortinet FortiWeb Path Traversal Vulnerability

  • CVE-2025-25257criticalAktiv ausgenutzt18. Juli 2025

    Fortinet FortiWeb SQL Injection Vulnerability

  • CVE-2025-32756criticalAktiv ausgenutzt14. Mai 2025

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

  • CVE-2024-47575criticalAktiv ausgenutzt23. Okt. 2024

    Fortinet FortiManager Missing Authentication Vulnerability

  • CVE-2024-23113criticalAktiv ausgenutzt09. Okt. 2024

    Fortinet Multiple Products Format String Vulnerability

  • CVE-2023-48788criticalAktiv ausgenutzt25. März 2024

    Fortinet FortiClient EMS SQL Injection Vulnerability

  • CVE-2024-21762criticalAktiv ausgenutzt09. Feb. 2024

    Fortinet FortiOS Out-of-Bound Write Vulnerability

  • CVE-2022-41328criticalAktiv ausgenutzt14. März 2023

    Fortinet FortiOS Path Traversal Vulnerability

  • CVE-2022-40684criticalAktiv ausgenutzt11. Okt. 2022

    Fortinet Multiple Products Authentication Bypass Vulnerability

  • CVE-2018-13374criticalAktiv ausgenutzt08. Sept. 2022

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

  • CVE-2018-13382criticalAktiv ausgenutzt10. Jan. 2022

    Fortinet FortiOS and FortiProxy Improper Authorization

  • CVE-2018-13383criticalAktiv ausgenutzt10. Jan. 2022

    Fortinet FortiOS and FortiProxy Out-of-bounds Write

  • CVE-2018-13379criticalAktiv ausgenutzt03. Nov. 2021

    Fortinet FortiOS SSL VPN Path Traversal Vulnerability

  • WID-SEC-2026-2330mediumCVSS 7.516. Juli 2026

    Affected products: Fortinet FortiSIEM

  • CVE-2026-59838mediumCVSS 5.315. Juli 2026

    A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6…

  • WID-SEC-2026-2332highCVSS 8.615. Juli 2026

    Affected products: Fortinet FortiSandbox

  • WID-SEC-2026-2331mediumCVSS 7.515. Juli 2026

    Affected products: Fortinet FortiClient

  • WID-SEC-2026-2329lowCVSS 4.315. Juli 2026

    Affected products: Fortinet FortiOS, Fortinet FortiProxy

  • WID-SEC-2026-2328mediumCVSS 6.615. Juli 2026

    Affected products: Fortinet FortiOS, Fortinet FortiProxy

  • CVE-2025-43892mediumCVSS 4.114. Juli 2026

    A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow…

  • CVE-2026-59840mediumCVSS 4.114. Juli 2026

    A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions…

  • CVE-2026-23573mediumCVSS 6.114. Juli 2026

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all…

  • CVE-2025-62826lowCVSS 3.114. Juli 2026

    An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all…

  • CVE-2026-59839mediumCVSS 5.014. Juli 2026

    A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all…

  • CVE-2025-62675lowCVSS 3.414. Juli 2026

    An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all…

  • CVE-2026-59836mediumCVSS 6.714. Juli 2026

    A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to…

  • CVE-2026-59841mediumCVSS 6.914. Juli 2026

    A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via…

  • CVE-2025-53379highCVSS 7.014. Juli 2026

    A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive…

  • CVE-2026-59835highCVSS 7.714. Juli 2026

    A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC…

  • CVE-2026-59837mediumCVSS 5.914. Juli 2026

    A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all…

  • WID-SEC-2026-1836highCVSS 9.810. Juni 2026

    Affected products: Fortinet FortiSandbox

  • WID-SEC-2026-1837mediumCVSS 6.710. Juni 2026

    Affected products: Fortinet FortiOS, Fortinet FortiProxy

  • WID-SEC-2026-1838mediumCVSS 4.910. Juni 2026

    Affected products: Fortinet FortiPortal

  • CVE-2025-67862mediumCVSS 6.009. Juni 2026

    An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0…

  • CVE-2026-49938mediumCVSS 6.209. Juni 2026

    A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access…

  • WID-SEC-2026-1509highCVSS 9.813. Mai 2026

    Affected products: Fortinet FortiAuthenticator

  • WID-SEC-2026-1495highCVSS 9.813. Mai 2026

    Affected products: Fortinet FortiSandbox

  • WID-SEC-2026-1494mediumCVSS 5.313. Mai 2026

    Affected products: Fortinet FortiAnalyzer, Fortinet FortiManager

  • WID-SEC-2026-1493mediumCVSS 7.213. Mai 2026

    Affected products: Fortinet FortiMail

  • WID-SEC-2026-1492highCVSS 8.813. Mai 2026

    Affected products: Fortinet FortiOS

  • WID-SEC-2026-1491lowCVSS 2.313. Mai 2026

    Affected products: Fortinet FortiClient

  • CVE-2025-53870mediumCVSS 6.512. Mai 2026

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2…

  • CVE-2025-53680mediumCVSS 6.112. Mai 2026

    An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0…

  • CVE-2025-67604mediumCVSS 5.212. Mai 2026

    A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all…

  • CVE-2025-53681mediumCVSS 6.312. Mai 2026

    An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0…

  • CVE-2025-53844highCVSS 8.312. Mai 2026

    A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or…

  • CVE-2026-25690mediumCVSS 4.012. Mai 2026

    An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3…

  • CVE-2026-44279mediumCVSS 5.012. Mai 2026

    A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may…

  • CVE-2026-44278lowCVSS 2.112. Mai 2026

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via…

  • CVE-2026-25088mediumCVSS 5.112. Mai 2026

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2…

  • CVE-2026-44277criticalCVSS 9.112. Mai 2026

    A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may…

  • CVE-2026-26083criticalCVSS 9.112. Mai 2026

    A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all…

  • WID-SEC-2026-1094highCVSS 9.820. Apr. 2026

    Affected products: Fortinet FortiSandbox

  • WID-SEC-2026-1091mediumCVSS 6.716. Apr. 2026

    Affected products: Fortinet FortiWeb

  • WID-SEC-2026-1122mediumCVSS 7.216. Apr. 2026

    Affected products: Fortinet FortiWeb

  • WID-SEC-2026-1092mediumCVSS 7.615. Apr. 2026

    Affected products: Fortinet FortiClient

  • WID-SEC-2026-1095mediumCVSS 6.515. Apr. 2026

    Affected products: Fortinet FortiOS

  • WID-SEC-2026-1096mediumCVSS 6.015. Apr. 2026

    Affected products: Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitch

  • WID-SEC-2026-1093highCVSS 8.115. Apr. 2026

    Affected products: Fortinet FortiManager, Fortinet FortiAnalyzer

  • WID-SEC-2026-1097mediumCVSS 5.415. Apr. 2026

    Affected products: Fortinet FortiVoice

  • CVE-2026-40688mediumCVSS 6.714. Apr. 2026

    An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote…

  • CVE-2025-61624mediumCVSS 5.414. Apr. 2026

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2…

  • CVE-2026-39813criticalCVSS 9.114. Apr. 2026

    A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially…

  • CVE-2026-22828highCVSS 7.314. Apr. 2026

    A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute…

  • CVE-2025-53847mediumCVSS 6.214. Apr. 2026

    A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through…

  • WID-SEC-2026-0962criticalCVSS 9.807. Apr. 2026

    Affected products: Fortinet FortiClient

  • WID-SEC-2026-0343highCVSS 9.831. März 2026

    Affected products: Fortinet FortiClient

  • WID-SEC-2026-0683highCVSS 8.811. März 2026

    Affected products: Fortinet FortiSwitch

  • WID-SEC-2026-0679mediumCVSS 7.211. März 2026

    Affected products: Fortinet FortiSandbox

  • WID-SEC-2026-0662highCVSS 8.111. März 2026

    Affected products: Fortinet FortiWeb

  • WID-SEC-2026-0672lowCVSS 4.311. März 2026

    Affected products: Fortinet FortiSIEM

  • WID-SEC-2026-0671mediumCVSS 7.211. März 2026

    Affected products: Fortinet FortiManager, Fortinet FortiAnalyzer

  • WID-SEC-2026-0670mediumCVSS 6.011. März 2026

    Affected products: Fortinet FortiAnalyzer

  • WID-SEC-2026-0669highCVSS 8.111. März 2026

    Affected products: Fortinet FortiManager

  • WID-SEC-2026-0665mediumCVSS 7.811. März 2026

    Affected products: Fortinet FortiClient

  • WID-SEC-2026-0663lowCVSS 4.011. März 2026

    Affected products: Fortinet FortiMail, Fortinet FortiRecorder, Fortinet FortiVoice

  • CVE-2026-22629lowCVSS 3.410. März 2026

    An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions…

  • CVE-2025-68648mediumCVSS 6.510. März 2026

    A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer…

  • CVE-2026-25836mediumCVSS 6.710. März 2026

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a…

  • CVE-2025-64157mediumCVSS 6.710. Feb. 2026

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions…

  • CVE-2025-62439lowCVSS 3.810. Feb. 2026

    An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all…

  • CVE-2025-55018mediumCVSS 5.210. Feb. 2026

    An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all…

  • CVE-2025-25249highCVSS 7.413. Jan. 2026

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all…

  • CVE-2025-59719criticalCVSS 9.109. Dez. 2025

    An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated…

  • CVE-2025-62631mediumCVSS 5.309. Dez. 2025

    An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows…

  • CVE-2025-53843mediumCVSS 6.918. Nov. 2025

    A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

  • CVE-2025-54821lowCVSS 1.818. Nov. 2025

    An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions…

  • CVE-2025-58413mediumCVSS 6.918. Nov. 2025

    A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

  • CVE-2025-31514lowCVSS 2.614. Okt. 2025

    A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions…

  • CVE-2025-31366mediumCVSS 4.514. Okt. 2025

    An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all…

  • CVE-2025-25253mediumCVSS 6.814. Okt. 2025

    An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and…

  • CVE-2025-57740mediumCVSS 6.714. Okt. 2025

    An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM…

  • CVE-2025-47890lowCVSS 2.514. Okt. 2025

    An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all…

  • CVE-2025-58903lowCVSS 2.514. Okt. 2025

    An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference…

  • CVE-2025-22862mediumCVSS 6.302. Okt. 2025

    An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through…

  • CVE-2024-26009highCVSS 7.912. Aug. 2025

    An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions…

  • CVE-2025-25248mediumCVSS 4.812. Aug. 2025

    An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions…

  • CVE-2025-53744mediumCVSS 6.812. Aug. 2025

    An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions…

  • CVE-2025-25250lowCVSS 3.910. Juni 2025

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions…

  • CVE-2025-24471mediumCVSS 6.010. Juni 2025

    An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via…

  • CVE-2023-36640mediumCVSS 6.514. Mai 2024

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all…

  • CVE-2023-45583mediumCVSS 6.514. Mai 2024

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all…

  • CVE-2024-23108criticalCVSS 9.705. Feb. 2024

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via…

Welche Register beigetragen haben

RegisterBetreiberEinträgeNeuester Eintrag
European Vulnerability DatabaseENISA, Europäische Union6215. Juli 2026
CERT-Bund SicherheitshinweiseBSI, Bundesrepublik Deutschland3316. Juli 2026
Katalog bekannt ausgenutzter SchwachstellenCISA, Vereinigte Staaten2016. Juli 2026

Die Zahlen hier sind die rohen Registertreffer zu Fortinet, vor der Zuordnung. Genau deshalb sind sie größer als die Liste darüber.

Fragen, die diese Seite beantwortet

Wie viele Schwachstellen hat Fortinet?

110 Meldungen in diesem Bestand sind von einem Register einem Produkt von Fortinet zugeordnet. Das ist nicht dasselbe wie die Zahl der Schwachstellen in den Produkten, und die kennt keine öffentliche Quelle. Es ist die Zahl dessen, was gefunden, offengelegt und veröffentlicht wurde, und die hängt daran, wie intensiv die Produkte geprüft werden und wie offen der Anbieter damit umgeht.

Werden Schwachstellen in Produkten von Fortinet aktiv ausgenutzt?

20 der 110 Einträge stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen, der Lücken mit bestätigter Ausnutzung in freier Wildbahn führt. Sie stehen in der Liste oben. Ob einer davon Ihre Installation betrifft, hängt an den Versionen und Komponenten, die Sie betreiben.

Warum zeigt diese Seite weniger CVEs zu Fortinet als andere Seiten?

Weil eine Stichwortsuche nach einem Firmennamen auch Meldungen über Produkte anderer Unternehmen zurückgibt, die den Namen nur nebenbei erwähnen. Diese Seite lässt sie weg. 0 Registereinträge nennen Fortinet, ohne eines seiner Produkte als betroffen zu benennen. Ein Spiegel, der sie mitführt, erzeugt eine längere Seite und eine falsche Zahl.

Woher stammen die Meldungen zu Fortinet auf dieser Seite?

Aus diesen Registern: European Vulnerability Database, betrieben von ENISA, Europäische Union; CERT-Bund Sicherheitshinweise, betrieben von BSI, Bundesrepublik Deutschland; Katalog bekannt ausgenutzter Schwachstellen, betrieben von CISA, Vereinigte Staaten. Jeder Eintrag verlinkt zurück auf das Register, das ihn veröffentlicht hat, und trägt das Datum, das dieses Register nennt. Führen mehrere Register dieselbe Schwachstelle, steht sie einmal da, mit einem Link auf jedes, statt doppelt gezählt zu werden.

Heißt eine lange Liste, dass Fortinet unsicher ist?

Nein. Ein Register hält fest, was Forschende gefunden und was der Anbieter offengelegt hat. Ein weit verbreitetes Produkt mit einem funktionierenden Offenlegungsprozess sammelt deshalb mehr Einträge als eines, das niemand prüft. Eine kurze Liste kann genauso gut für eine kleine Installationsbasis stehen oder für einen Anbieter, der wenig veröffentlicht. Diese Seite gibt den Bestand wieder und bewertet den Anbieter nicht, denn ob das für Sie tragbar ist, hängt an Ihrer Risikobereitschaft, Ihrem Compliance-Umfang und den Alternativen, die Sie abwägen.

Eine Liste von Meldungen ist noch keine Risikobewertung

Es zählt, welche davon die Komponenten betreffen, die Sie tatsächlich betreiben, in der Konfiguration, in der Sie sie betreiben, und ob das neben den Alternativen Ihrer engeren Auswahl tragbar ist. DecisionOS liest denselben Bestand an den Kriterien einer konkreten Entscheidung und liefert ein Memo, das vor Geschäftsführung und Revision standhält.

Der vollständige Bestand zu Fortinet, samt Quellen und offenen Fragen

Fortinet Schwachstellen: alle 110 Meldungen im Bestand, mit Quelle | DecisionOS by nexalign