fortinet

1,122 tracked vulnerabilities.

CVE-2026-21741 LOW
FortiNAC-F 7.2.0-7.6.5 - Authenticated Open Redirect via Crafted CSV File
Apr 14, 2026
CVSS 2.4
EPSS 0.00
CVE-2026-35616 CRITICAL KEVNUCLEI
Fortinet FortiClientEMS 7.4.5-7.4.6 - Command Injection
Apr 04, 2026
CVSS 9.8
EPSS 0.43
CVE-2026-30897 MEDIUM
Fortinet FortiWeb - Buffer Overflow
Mar 10, 2026
CVSS 6.6
EPSS 0.00
CVE-2026-25972 MEDIUM
Fortinet FortiSIEM 7.4.0, 7.3.0-7.3.4 - XSS
Mar 10, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-25836 HIGH
Fortinet FortiSandbox Cloud 5.0.4 - Command Injection
Mar 10, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-25689 MEDIUM
Fortinet FortiDeceptor - Command Injection
Mar 10, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-24641 LOW
FortiWeb 7.0.0-7.6.6, 8.0.0-8.0.2 - Authenticated Denial of Service via HTTP Request
Mar 10, 2026
CVSS 2.7
EPSS 0.00
CVE-2026-24640 MEDIUM
FortiWeb 7.0.2-8.0.2 - Buffer Overflow
Mar 10, 2026
CVSS 6.6
EPSS 0.00
CVE-2026-24018 HIGH
FortiClientLinux 7.2.2-7.4.4 - Privilege Escalation
Mar 10, 2026
CVSS 7.8
EPSS 0.00
CVE-2026-24017 HIGH
FortiWeb 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, 8.0.0-8.0.2 - Authentication Rate-Limit Bypass
Mar 10, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-22629 LOW
Fortinet FortiAnalyzer/FortiManager - Auth Bypass
Mar 10, 2026
CVSS 3.7
EPSS 0.00
CVE-2026-22628 MEDIUM
Fortinet FortiSwitchAXFixed 1.0.0-1.0.1 - Command Injection
Mar 10, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-22627 HIGH
Fortinet FortiSwitchAXFixed 1.0.0-1.0.1 - Buffer Overflow
Mar 10, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-22572 HIGH
Fortinet FortiAnalyzer 7.6.0-7.6.3 - Auth Bypass
Mar 10, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-22153 HIGH
FortiOS 7.6.0-7.6.4 - Unauthenticated Authentication Bypass via LDAP Configuration
Feb 10, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-21743 HIGH
Fortinet FortiAuthenticator 6.3.0-6.6.6 - Missing Authorization for Local User Modification via File Upload
Feb 10, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-21643 CRITICAL KEVNUCLEI
Fortinet FortiClientEMS <7.4.4 - SQL Injection
Feb 06, 2026
CVSS 9.8
EPSS 0.63
CVE-2026-25815 LOW
Fortinet FortiOS <7.6.6 - Info Disclosure
Feb 05, 2026
CVSS 3.2
EPSS 0.00
CVE-2026-24858 CRITICAL KEV
Fortinet FortiAnalyzer 7.0.0-7.0.15, 7.2.0-7.2.11, 7.4.0-7.4.9, 7.6.0-7.6.5 - Authentication Bypass via FortiCloud SSO
Jan 27, 2026
CVSS 9.8
EPSS 0.04
CVE-2025-67604 MEDIUM
FortiAnalyzer and FortiManager - Authenticated Denial of Service via Multiple Crafted HTTP Requests
May 12, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-53870 MEDIUM
Fortinet FortiAP - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
May 12, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-53844 HIGH
FortiOS 7.6.0-7.6.3, 7.4.0-7.4.8, 7.2.0-7.2.11 - Out-of-bounds Write via Specially Crafted Packets
May 12, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-53681 HIGH
Fortinet FortiMail - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
May 12, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-53680 MEDIUM
Fortinet FortiAP - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
May 12, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-68649 MEDIUM
Fortinet FortiManager and FortiAnalyzer <= 7.6.4, <= 7.4.7, 7.2 all, 7.0 all - Path Traversal via CLI Requests
Apr 14, 2026
CVSS 6.0
EPSS 0.00