Network security
Fortinet advisories: every record the registers tie to its products
In one line
110 advisories are attributed to Fortinet products in this record, covering November 2021 to July 2026, and 20 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 0 register entries mention Fortinet without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.
Attributed
110
tied to a named product
Known exploited
20
in the CISA catalogue
Rated critical
26
by the register
Last checked
Jul 24, 2026
sources re-queried
Why this list is shorter than a CVE mirror
The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Fortinet, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.
0 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.
95 of the 110 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.
The full list, most recently exploited and most recent first
Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.
- CVE-2026-39808criticalCVSS 9.1Known exploitedJul 16, 2026
Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-25089criticalCVSS 9.1Known exploitedJul 16, 2026
Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-21643criticalKnown exploitedApr 13, 2026
Fortinet FortiClient EMS SQL Injection Vulnerability
- CVE-2026-35616criticalCVSS 9.1Known exploitedApr 06, 2026
Fortinet FortiClient EMS Improper Access Control Vulnerability
- CVE-2026-24858criticalCVSS 9.4Known exploitedJan 27, 2026
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVE-2025-59718criticalCVSS 9.1Known exploitedDec 16, 2025
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
- CVE-2025-58034criticalKnown exploitedNov 18, 2025
Fortinet FortiWeb OS Command Injection Vulnerability
- CVE-2025-64446criticalKnown exploitedNov 14, 2025
Fortinet FortiWeb Path Traversal Vulnerability
- CVE-2025-25257criticalKnown exploitedJul 18, 2025
Fortinet FortiWeb SQL Injection Vulnerability
- CVE-2025-32756criticalKnown exploitedMay 14, 2025
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
- CVE-2024-47575criticalKnown exploitedOct 23, 2024
Fortinet FortiManager Missing Authentication Vulnerability
- CVE-2024-23113criticalKnown exploitedOct 09, 2024
Fortinet Multiple Products Format String Vulnerability
- CVE-2023-48788criticalKnown exploitedMar 25, 2024
Fortinet FortiClient EMS SQL Injection Vulnerability
- CVE-2024-21762criticalKnown exploitedFeb 09, 2024
Fortinet FortiOS Out-of-Bound Write Vulnerability
- CVE-2022-41328criticalKnown exploitedMar 14, 2023
Fortinet FortiOS Path Traversal Vulnerability
- CVE-2022-40684criticalKnown exploitedOct 11, 2022
Fortinet Multiple Products Authentication Bypass Vulnerability
- CVE-2018-13374criticalKnown exploitedSep 08, 2022
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
- CVE-2018-13382criticalKnown exploitedJan 10, 2022
Fortinet FortiOS and FortiProxy Improper Authorization
- CVE-2018-13383criticalKnown exploitedJan 10, 2022
Fortinet FortiOS and FortiProxy Out-of-bounds Write
- CVE-2018-13379criticalKnown exploitedNov 03, 2021
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
- WID-SEC-2026-2330mediumCVSS 7.5Jul 16, 2026
Affected products: Fortinet FortiSIEM
- CVE-2026-59838mediumCVSS 5.3Jul 15, 2026
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6…
- WID-SEC-2026-2332highCVSS 8.6Jul 15, 2026
Affected products: Fortinet FortiSandbox
- WID-SEC-2026-2331mediumCVSS 7.5Jul 15, 2026
Affected products: Fortinet FortiClient
- WID-SEC-2026-2329lowCVSS 4.3Jul 15, 2026
Affected products: Fortinet FortiOS, Fortinet FortiProxy
- WID-SEC-2026-2328mediumCVSS 6.6Jul 15, 2026
Affected products: Fortinet FortiOS, Fortinet FortiProxy
- CVE-2025-43892mediumCVSS 4.1Jul 14, 2026
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow…
- CVE-2026-59840mediumCVSS 4.1Jul 14, 2026
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions…
- CVE-2026-23573mediumCVSS 6.1Jul 14, 2026
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all…
- CVE-2025-62826lowCVSS 3.1Jul 14, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all…
- CVE-2026-59839mediumCVSS 5.0Jul 14, 2026
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all…
- CVE-2025-62675lowCVSS 3.4Jul 14, 2026
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all…
- CVE-2026-59836mediumCVSS 6.7Jul 14, 2026
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to…
- CVE-2026-59841mediumCVSS 6.9Jul 14, 2026
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via…
- CVE-2025-53379highCVSS 7.0Jul 14, 2026
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive…
- CVE-2026-59835highCVSS 7.7Jul 14, 2026
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC…
- CVE-2026-59837mediumCVSS 5.9Jul 14, 2026
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all…
- WID-SEC-2026-1836highCVSS 9.8Jun 10, 2026
Affected products: Fortinet FortiSandbox
- WID-SEC-2026-1837mediumCVSS 6.7Jun 10, 2026
Affected products: Fortinet FortiOS, Fortinet FortiProxy
- WID-SEC-2026-1838mediumCVSS 4.9Jun 10, 2026
Affected products: Fortinet FortiPortal
- CVE-2025-67862mediumCVSS 6.0Jun 09, 2026
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0…
- CVE-2026-49938mediumCVSS 6.2Jun 09, 2026
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access…
- WID-SEC-2026-1509highCVSS 9.8May 13, 2026
Affected products: Fortinet FortiAuthenticator
- WID-SEC-2026-1495highCVSS 9.8May 13, 2026
Affected products: Fortinet FortiSandbox
- WID-SEC-2026-1494mediumCVSS 5.3May 13, 2026
Affected products: Fortinet FortiAnalyzer, Fortinet FortiManager
- WID-SEC-2026-1493mediumCVSS 7.2May 13, 2026
Affected products: Fortinet FortiMail
- WID-SEC-2026-1492highCVSS 8.8May 13, 2026
Affected products: Fortinet FortiOS
- WID-SEC-2026-1491lowCVSS 2.3May 13, 2026
Affected products: Fortinet FortiClient
- CVE-2025-53870mediumCVSS 6.5May 12, 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2…
- CVE-2025-53680mediumCVSS 6.1May 12, 2026
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0…
- CVE-2025-67604mediumCVSS 5.2May 12, 2026
A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all…
- CVE-2025-53681mediumCVSS 6.3May 12, 2026
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0…
- CVE-2025-53844highCVSS 8.3May 12, 2026
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or…
- CVE-2026-25690mediumCVSS 4.0May 12, 2026
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3…
- CVE-2026-44279mediumCVSS 5.0May 12, 2026
A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may…
- CVE-2026-44278lowCVSS 2.1May 12, 2026
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via…
- CVE-2026-25088mediumCVSS 5.1May 12, 2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2…
- CVE-2026-44277criticalCVSS 9.1May 12, 2026
A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may…
- CVE-2026-26083criticalCVSS 9.1May 12, 2026
A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all…
- WID-SEC-2026-1094highCVSS 9.8Apr 20, 2026
Affected products: Fortinet FortiSandbox
- WID-SEC-2026-1091mediumCVSS 6.7Apr 16, 2026
Affected products: Fortinet FortiWeb
- WID-SEC-2026-1122mediumCVSS 7.2Apr 16, 2026
Affected products: Fortinet FortiWeb
- WID-SEC-2026-1092mediumCVSS 7.6Apr 15, 2026
Affected products: Fortinet FortiClient
- WID-SEC-2026-1095mediumCVSS 6.5Apr 15, 2026
Affected products: Fortinet FortiOS
- WID-SEC-2026-1096mediumCVSS 6.0Apr 15, 2026
Affected products: Fortinet FortiOS, Fortinet FortiProxy, Fortinet FortiSwitch
- WID-SEC-2026-1093highCVSS 8.1Apr 15, 2026
Affected products: Fortinet FortiManager, Fortinet FortiAnalyzer
- WID-SEC-2026-1097mediumCVSS 5.4Apr 15, 2026
Affected products: Fortinet FortiVoice
- CVE-2026-40688mediumCVSS 6.7Apr 14, 2026
An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote…
- CVE-2025-61624mediumCVSS 5.4Apr 14, 2026
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2…
- CVE-2026-39813criticalCVSS 9.1Apr 14, 2026
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially…
- CVE-2026-22828highCVSS 7.3Apr 14, 2026
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute…
- CVE-2025-53847mediumCVSS 6.2Apr 14, 2026
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through…
- WID-SEC-2026-0962criticalCVSS 9.8Apr 07, 2026
Affected products: Fortinet FortiClient
- WID-SEC-2026-0343highCVSS 9.8Mar 31, 2026
Affected products: Fortinet FortiClient
- WID-SEC-2026-0683highCVSS 8.8Mar 11, 2026
Affected products: Fortinet FortiSwitch
- WID-SEC-2026-0679mediumCVSS 7.2Mar 11, 2026
Affected products: Fortinet FortiSandbox
- WID-SEC-2026-0662highCVSS 8.1Mar 11, 2026
Affected products: Fortinet FortiWeb
- WID-SEC-2026-0672lowCVSS 4.3Mar 11, 2026
Affected products: Fortinet FortiSIEM
- WID-SEC-2026-0671mediumCVSS 7.2Mar 11, 2026
Affected products: Fortinet FortiManager, Fortinet FortiAnalyzer
- WID-SEC-2026-0670mediumCVSS 6.0Mar 11, 2026
Affected products: Fortinet FortiAnalyzer
- WID-SEC-2026-0669highCVSS 8.1Mar 11, 2026
Affected products: Fortinet FortiManager
- WID-SEC-2026-0665mediumCVSS 7.8Mar 11, 2026
Affected products: Fortinet FortiClient
- WID-SEC-2026-0663lowCVSS 4.0Mar 11, 2026
Affected products: Fortinet FortiMail, Fortinet FortiRecorder, Fortinet FortiVoice
- CVE-2026-22629lowCVSS 3.4Mar 10, 2026
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions…
- CVE-2025-68648mediumCVSS 6.5Mar 10, 2026
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer…
- CVE-2026-25836mediumCVSS 6.7Mar 10, 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a…
- CVE-2025-64157mediumCVSS 6.7Feb 10, 2026
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions…
- CVE-2025-62439lowCVSS 3.8Feb 10, 2026
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all…
- CVE-2025-55018mediumCVSS 5.2Feb 10, 2026
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all…
- CVE-2025-25249highCVSS 7.4Jan 13, 2026
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all…
- CVE-2025-59719criticalCVSS 9.1Dec 09, 2025
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated…
- CVE-2025-62631mediumCVSS 5.3Dec 09, 2025
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows…
- CVE-2025-53843mediumCVSS 6.9Nov 18, 2025
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…
- CVE-2025-54821lowCVSS 1.8Nov 18, 2025
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions…
- CVE-2025-58413mediumCVSS 6.9Nov 18, 2025
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…
- CVE-2025-31514lowCVSS 2.6Oct 14, 2025
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions…
- CVE-2025-31366mediumCVSS 4.5Oct 14, 2025
An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all…
- CVE-2025-25253mediumCVSS 6.8Oct 14, 2025
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and…
- CVE-2025-57740mediumCVSS 6.7Oct 14, 2025
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM…
- CVE-2025-47890lowCVSS 2.5Oct 14, 2025
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all…
- CVE-2025-58903lowCVSS 2.5Oct 14, 2025
An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference…
- CVE-2025-22862mediumCVSS 6.3Oct 02, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through…
- CVE-2024-26009highCVSS 7.9Aug 12, 2025
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions…
- CVE-2025-25248mediumCVSS 4.8Aug 12, 2025
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions…
- CVE-2025-53744mediumCVSS 6.8Aug 12, 2025
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions…
- CVE-2025-25250lowCVSS 3.9Jun 10, 2025
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions…
- CVE-2025-24471mediumCVSS 6.0Jun 10, 2025
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via…
- CVE-2023-36640mediumCVSS 6.5May 14, 2024
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all…
- CVE-2023-45583mediumCVSS 6.5May 14, 2024
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all…
- CVE-2024-23108criticalCVSS 9.7Feb 05, 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via…
Which registers contributed
| Register | Operated by | Entries | Latest |
|---|---|---|---|
| European Vulnerability Database | ENISA, European Union | 62 | Jul 15, 2026 |
| CERT-Bund security advisories | BSI, Federal Republic of Germany | 33 | Jul 16, 2026 |
| Known Exploited Vulnerabilities catalogue | CISA, United States | 20 | Jul 16, 2026 |
The entry counts here are the raw register totals for Fortinet, before attribution. They are larger than the list above for exactly that reason.
Questions this page answers
How many vulnerabilities does Fortinet have?
110 advisories in this record are tied by a register to a product of Fortinet. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.
Are any Fortinet vulnerabilities being actively exploited?
20 of the 110 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.
Why does this page show fewer CVEs for Fortinet than other sites?
Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 0 register entries name Fortinet without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.
Where do the Fortinet advisories on this page come from?
From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.
Does a long advisory list mean Fortinet is insecure?
No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.
A list of advisories is not a risk assessment
What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.
The full Fortinet record, including sources and open questions
