Fortinet / FortiOS
277 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84392 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 a… | LOW | 2.7 | Sep 8, 2026 |
| CVE-2026-84393 | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacke… | HIGH | 8.1 | Sep 8, 2026 |
| CVE-2026-70466 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWe… | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2026-71407 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypas… | HIGH | 8.1 | Aug 12, 2026 |
| CVE-2026-71408 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all version… | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2026-59840 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fort… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2025-43892 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fort… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-23573 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through… | MEDIUM | 6.1 | Jul 14, 2026 |
| CVE-2026-59839 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7… | MEDIUM | 5.5 | Jul 14, 2026 |
| CVE-2025-62826 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2025-62675 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-59837 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all v… | MEDIUM | 6.6 | Jul 14, 2026 |
| CVE-2025-67862 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 t… | MEDIUM | 6.7 | Jun 9, 2026 |
| CVE-2025-53844 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execu… | HIGH | 8.8 | May 12, 2026 |
| CVE-2025-61624 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2025-53847 | A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11… | HIGH | 8.8 | Apr 14, 2026 |
| CVE-2025-62439 | An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 thro… | MEDIUM | 4.2 | Feb 10, 2026 |
| CVE-2025-68686 KEV | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 thro… | MEDIUM | 5.9 | Feb 10, 2026 |
| CVE-2025-64157 | A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11,… | HIGH | 7.2 | Feb 10, 2026 |
| CVE-2025-55018 | An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 al… | MEDIUM | 5.8 | Feb 10, 2026 |
| CVE-2026-22153 | An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacke… | HIGH | 8.1 | Feb 10, 2026 |
| CVE-2026-25815 | Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 thro… | LOW | 3.2 | Feb 5, 2026 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer… | CRITICAL | 9.8 | Jan 27, 2026 |
| CVE-2025-25249 KEV | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 th… | CRITICAL | 9.8 | Jan 13, 2026 |
| CVE-2024-40593 | A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAn… | MEDIUM | 5.9 | Dec 11, 2025 |
Showing 1 to 25 of 277 CVEs