Fortinet Vulnerabilities and Affected Products
Vulnerabilities associated with FortiAuthenticator.
Products
Clear product- FortiOS182 vulnerabilities
- FortiProxy106 vulnerabilities
- FortiManager82 vulnerabilities
- FortiWeb75 vulnerabilities
- FortiAnalyzer68 vulnerabilities
- FortiSandbox47 vulnerabilities
- Fortinet FortiOS39 vulnerabilities
- FortiPAM37 vulnerabilities
- FortiADC33 vulnerabilities
- FortiClientWindows27 vulnerabilities
- Fortinet FortiWeb27 vulnerabilities
- FortiPortal25 vulnerabilities
- FortiNAC23 vulnerabilities
- FortiSIEM23 vulnerabilities
- FortiMail22 vulnerabilities
- FortiClientEMS21 vulnerabilities
- FortiSwitchManager20 vulnerabilities
- FortiVoice20 vulnerabilities
- FortiClientMac15 vulnerabilities
- Fortinet FortiMail15 vulnerabilities
- FortiManager Cloud14 vulnerabilities
- FortiRecorder14 vulnerabilities
- FortiSOAR14 vulnerabilities
- FortiWLM14 vulnerabilities
- FortiNDR13 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-53379HIGH | Generated title:Fortinet FortiAuthenticator Out-of-Bounds Read Information DisclosureA out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. CWE-125Jul 14, 2026 | CVSS7.0v3.1 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44277CRITICAL | Generated title:Fortinet FortiAuthenticator Improper Access Control Leading to Remote Code ExecutionA improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests. CWE-284May 12, 2026 | CVSS9.1v3.1 | EPSS0.551% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21743MEDIUM | Generated title:Fortinet FortiAuthenticator Missing Authorization VulnerabilityA missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected endpoint. CWE-862Feb 10, 2026 | CVSS6.8v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints CWE-425Dec 9, 2025 | CVSS2.6v3.1 | EPSS0.226% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests. CWE-284Dec 9, 2025 | CVSS2.6v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-23439MEDIUM | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver CWE-610Jan 22, 2025 | CVSS4.1v3.1 | EPSS0.449% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23664MEDIUM | A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL. CWE-601Jun 3, 2024 | CVSS5.8v3.1 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-22302MEDIUM | A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem. CWE-312Jul 11, 2023 | CVSS5.3v3.1 | EPSS0.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-35850MEDIUM | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected cross site scripting (XSS) attack via the "reset-password" page. | CVSS4.2v3.1 | EPSS0.494% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. CWE-307Mar 9, 2023 | CVSS3.5v3.1 | EPSS1.81% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2021-24005MEDIUM | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacker with access to the files or the CLI configuration to decrypt the sensitive data, via knowledge of the hard-coded key. CWE-798Jul 6, 2021 | CVSS4.0v3.1 | EPSS0.563% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |