fortinet

1,122 tracked vulnerabilities.

CVE-2026-44279 MEDIUM
FortiTokenAndroid 6.2, 6.1, 5.2 - Improper Export of Android Application Components
May 12, 2026
CVSS 5.5
EPSS 0.00
CVE-2026-44278 LOW
FortiClientWindows 7.2.0-7.4.2 - Information Disclosure via Hard-coded Cryptographic Key
May 12, 2026
CVSS 2.3
EPSS 0.00
CVE-2026-44277 CRITICAL
FortiAuthenticator 8.0.0-8.0.2, 6.5.0-6.5.6, 6.6.0-6.6.8, 6.4.0-6.4.10 - Improper Access Control
May 12, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-26083 CRITICAL
FortiSandbox and FortiSandbox Cloud - Unauthenticated Remote Code Execution via HTTP Requests
May 12, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-25690 MEDIUM
Fortinet FortiDeceptor - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
May 12, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-25088 MEDIUM
Fortinet FortiNDR - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
May 12, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-40688 HIGH
FortiWeb 8.0.0-8.0.3, 7.6.0-7.6.6, 7.4.0-7.4.11 - Authenticated Remote Code Execution via Crafted HTTP Requests
Apr 14, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-39815 HIGH
FortiDDoS-F 7.2.1-7.2.2 - SQL Injection via Crafted HTTP Requests
Apr 14, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-39814 MEDIUM
FortiWeb 8.0.0-8.0.2, 7.6.0-7.6.6, 7.4.1-7.4.12, 7.0.10-7.0.12 - Relative Path Traversal
Apr 14, 2026
CVSS 6.7
EPSS 0.00
CVE-2026-39813 CRITICAL
FortiSandbox 4.4.0-4.4.8 and 5.0.0-5.0.5 - Path Traversal via '../filedir'
Apr 14, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-39812 MEDIUM
FortiSandbox 4.2-5.0.5 - Cross-Site Scripting
Apr 14, 2026
CVSS 4.8
EPSS 0.00
CVE-2026-39811 MEDIUM
FortiWeb 8.0.0-8.0.3, 7.6.0-7.6.6, 7.4.0-7.4.12, 7.2.0-7.2.12, 7.0.0-7.0.12 - Denial of Service via Integer Overflow
Apr 14, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-39810 MEDIUM
FortiClientEMS 7.4.0-7.4.5 - Information Disclosure via Hard-coded Cryptographic Key
Apr 14, 2026
CVSS 6.0
EPSS 0.00
CVE-2026-39809 MEDIUM
FortiClientEMS 7.0.0-7.0.12, 7.2.0-7.2.12, 7.4.0-7.4.5 - SQL Injection
Apr 14, 2026
CVSS 6.7
EPSS 0.00
CVE-2026-39808 CRITICAL NUCLEI
FortiSandbox 4.4.0-4.4.8 - OS Command Injection
Apr 14, 2026
CVSS 9.8
EPSS 0.25
CVE-2026-27316 LOW
Fortinet FortiSandbox <5.0.5 - Info Disclosure
Apr 14, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-25691 MEDIUM
FortiSandbox 4.2.0-5.0.5 - Authenticated Path Traversal via HTTP Requests
Apr 14, 2026
CVSS 6.7
EPSS 0.00
CVE-2026-23708 HIGH
FortiSOAR PaaS 7.6.0-7.6.3 - Auth Bypass
Apr 14, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-22828 HIGH
FortiAnalyzer/FortiManager Cloud 7.6.2-7.6.4 - Unauthenticated RCE via Heap Overflow
Apr 14, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-22576 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
Apr 14, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-22574 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
Apr 14, 2026
CVSS 4.1
EPSS 0.00
CVE-2026-22573 MEDIUM
FortiSOAR 7.3.0-7.6.3 - Authenticated Path Traversal via File Content Extraction
Apr 14, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-22155 MEDIUM
FortiSOAR 7.3-7.6 - Cleartext Transmission of Sensitive Information
Apr 14, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-22154 MEDIUM
FortiSOAR 7.3-7.6.3 - Authenticated Stored Cross-Site Scripting via HTTP Requests
Apr 14, 2026
CVSS 4.6
EPSS 0.00
CVE-2026-21742 MEDIUM
Fortinet FortiSOAR PaaS <7.6.2 - Info Disclosure
Apr 14, 2026
CVSS 5.7
EPSS 0.00