← Back to News Iceland Security Dashboard Browse all tags
fortinet

Fortinet

fortios 27fortiweb 21fortisandbox 12fortianalyzer 7multiple products 5fortios-and-fortiproxy 5fortimanager 5fortios and fortiproxy 4fortivoice 3fortisiem 3forticlientems 3forticlient-ems 3forticlient ems 3forticlient 3fortiauthenticator 3fortios-fortiproxy-fortiswitchmanager 2fortimail 2fortideceptor 2fortiap 2fortitoken_mobile 1

CVEs tagged with this vendor (80)

CVE-2026-21643 🚨 CVSS 9.8 FortiClient EMS
CVE-2026-21643 is a critical SQL injection vulnerability (CWE-89) in Fortinet FortiClientEMS 7.4.4, allowing unauthenticated attackers to execute unauthorized c…
CVE-2026-24858 🚨 CVSS 9.8 Multiple Products
CVE-2026-24858 is a critical authentication bypass vulnerability affecting multiple versions of Fortinet FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and F…
CVE-2026-35616 🚨 CVSS 9.8 FortiClient EMS
CVE-2026-35616 is a critical improper access control vulnerability (CWE-284) in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6, allowing unauthenticated a…
CVE-2018-13374 🚨 FortiOS and FortiADC
CVE-2018-13374 is an improper access control vulnerability (CWE-732) in Fortinet FortiOS versions 6.0.2, 5.6.7 and earlier, and FortiADC versions 6.1.0, 6.0.0 t…
CVE-2018-13379 🚨 FortiOS
CVE-2018-13379 is a critical path traversal vulnerability (CWE-22) in Fortinet FortiOS versions 6.0.0-6.0.4, 5.6.3-5.6.7, 5.4.6-5.4.12, and FortiProxy versions …
CVE-2018-13382 🚨 FortiOS and FortiProxy
CVE-2018-13382 is a critical improper authorization vulnerability (CWE-863) affecting Fortinet FortiOS versions 6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10, and Fort…
CVE-2018-13383 🚨 FortiOS and FortiProxy
CVE-2018-13383 is a memory corruption vulnerability (CWE-787) affecting Fortinet FortiOS versions 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.1…
CVE-2019-5591 🚨 FortiOS
CVE-2019-5591 is a vulnerability in Fortinet FortiOS that is currently listed on CISA's Known Exploited Vulnerabilities catalog as actively exploited in the wil…
CVE-2019-6693 🚨 FortiOS
CVE-2019-6693 is a crypto-weakness in Fortinet FortiOS where the use of a hard-coded cryptographic key in configuration backup files allows attackers to deciphe…
CVE-2020-12812 🚨 FortiOS
CVE-2020-12812 is a critical authentication bypass vulnerability in Fortinet FortiOS SSL VPN affecting versions 6.4.0, 6.2.0 through 6.2.3, and 6.0.9 and below.…
CVE-2021-44168 🚨 FortiOS
CVE-2021-44168 is a vulnerability in FortiOS versions prior to 7.0.3 affecting the 'execute restore src-vis' command, allowing local authenticated attackers to …
CVE-2022-40684 🚨 Multiple Products
CVE-2022-40684 is a critical authentication bypass vulnerability affecting Fortinet FortiOS versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy ver…
CVE-2022-41328 🚨 FortiOS
CVE-2022-41328 is a path traversal vulnerability (CWE-22) in Fortinet FortiOS versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, and prior to 6.4.11. It allows …
CVE-2022-42475 🚨 FortiOS
CVE-2022-42475 is a critical heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy SSL-VPN components, affecting versions 7.2.0 through 7.…
CVE-2023-27997 🚨 FortiOS and FortiProxy SSL-VPN
CVE-2023-27997 is a critical heap-based buffer overflow vulnerability affecting FortiOS and FortiProxy SSL-VPN services across multiple version branches. The fl…
CVE-2023-48788 🚨 FortiClient EMS
CVE-2023-48788 is a critical SQL injection vulnerability (CWE-89) affecting Fortinet FortiClient EMS versions 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10. The …
CVE-2024-21762 🚨 FortiOS
CVE-2024-21762 is a critical out-of-bounds write vulnerability (CWE-787) affecting Fortinet FortiOS and FortiProxy versions across multiple release branches, al…
CVE-2024-23113 🚨 Multiple Products
CVE-2024-23113 is a critical remote code execution vulnerability in Fortinet FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager products, classified as CWE-1…
CVE-2024-47575 🚨 FortiManager
CVE-2024-47575 is a critical authentication bypass vulnerability (CWE-306) affecting multiple versions of Fortinet FortiManager and FortiManager Cloud, allowing…
CVE-2024-55591 🚨 FortiOS and FortiProxy
CVE-2024-55591 is a critical authentication bypass vulnerability affecting FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 an…
CVE-2025-24472 🚨 FortiOS and FortiProxy
CVE-2025-24472 is a HIGH severity (CVSS 8.1) Authentication Bypass Using an Alternate Path or Channel vulnerability affecting FortiOS versions 7.0.0 through 7.0…
CVE-2025-25257 🚨 FortiWeb
CVE-2025-25257 is a critical SQL injection vulnerability (CWE-89) affecting Fortinet FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7…
CVE-2025-32756 🚨 Multiple Products
CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting multiple versions of Fortinet FortiCamera, FortiMail, FortiNDR, FortiRecorder, …
CVE-2025-58034 🚨 FortiWeb
CVE-2025-58034 is a command injection vulnerability in Fortinet FortiWeb versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through …
CVE-2025-59718 🚨 Multiple Products
CVE-2025-59718 is a critical authentication bypass vulnerability affecting multiple versions of Fortinet FortiOS, FortiProxy, and FortiSwitchManager products. I…
CVE-2025-64446 🚨 FortiWeb
CVE-2025-64446 is a critical path traversal vulnerability (CWE-23) affecting Fortinet FortiWeb versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.4, 7.4.0 through …
CVE-2025-64155 CVSS 9.8 fortisiem
CVE-2025-64155 is a critical command injection vulnerability (CWE-78) in Fortinet FortiSIEM versions 6.7.0 through 7.4.0, allowing unauthorized code execution v…
CVE-2026-26083 CVSS 9.8 fortisandbox
CVE-2026-26083 is a critical missing authorization vulnerability (CWE-862) affecting multiple versions of Fortinet FortiSandbox and FortiSandbox PaaS. It allows…
CVE-2026-39808 CVSS 9.8 fortisandbox
CVE-2026-39813 CVSS 9.8 fortisandbox
CVE-2026-44277 CVSS 9.8 fortiauthenticator
CVE-2026-44277 is a critical improper access control vulnerability (CWE-284) in Fortinet FortiAuthenticator versions 8.0.0, 8.0.2, and 6.5.0 through 6.5.6, as w…
CVE-2025-52436 CVSS 8.8 fortisandbox
CVE-2025-53844 CVSS 8.8 fortios
CVE-2025-53844 is a high-severity out-of-bounds write vulnerability (CWE-787) affecting Fortinet FortiOS versions 7.6.0 through 7.6.3 and 7.4.0 through 7.4.8, a…
CVE-2026-39815 CVSS 8.8 fortiddos-f
CVE-2025-25249 CVSS 8.1 fortios
CVE-2025-54820 CVSS 8.1 fortimanager
CVE-2026-22153 CVSS 8.1 fortios
CVE-2026-22153 is a HIGH severity (CVSS 8.1) authentication bypass vulnerability in Fortinet FortiOS versions 7.6.0 through 7.6.4. It allows unauthenticated att…
CVE-2026-24017 CVSS 8.1 fortiweb
No NVD or KEV data was available for CVE-2026-24017. Consequently, no verified technical details regarding the vulnerability's nature, affected components, or s…
CVE-2026-24018 CVSS 7.8 forticlient
CVE-2025-53681 CVSS 7.2 fortimail
CVE-2025-53681 is a high-severity SQL injection vulnerability (CWE-89) affecting Fortinet FortiMail versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.5, and 7.2.0…
CVE-2025-59922 CVSS 7.2 forticlientems
CVE-2025-61848 CVSS 7.2 fortianalyzer
CVE-2025-66178 CVSS 7.2 fortiweb
CVE-2025-66178 is a command injection vulnerability (CWE-78) in Fortinet FortiWeb versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.11, 7.2.0…
CVE-2025-68648 CVSS 7.2 fortianalyzer
CVE-2026-21743 CVSS 7.2 fortiauthenticator
CVE-2026-22572 CVSS 7.2 fortianalyzer
CVE-2026-25836 CVSS 7.2 fortisandbox_cloud
CVE-2026-25836 is a command injection vulnerability (CWE-78) in Fortinet FortiSandbox Cloud 5.0.4 and FortiSandbox PaaS 5.0.4. It allows a privileged attacker w…
CVE-2026-40688 CVSS 7.2 fortiweb
CVE-2026-40688 is a high-severity out-of-bounds write vulnerability (CWE-787) affecting Fortinet FortiWeb versions 8.0.0 through 8.0.3, 7.6.0 through 7.6.6, and…
CVE-2025-62676 CVSS 7.1 forticlient
CVE-2025-68482 CVSS 6.9 fortimanager
CVE-2025-48418 CVSS 6.7 fortimanager
CVE-2025-53680 CVSS 6.7 fortiap
CVE-2025-53870 CVSS 6.7 fortiap
CVE-2025-64157 CVSS 6.7 fortios
CVE-2026-25691 CVSS 6.7 fortisandbox
CVE-2026-39809 CVSS 6.7 forticlientems
CVE-2026-39814 CVSS 6.7 fortiweb
CVE-2026-39814 is a medium severity path traversal vulnerability (CWE-23) affecting Fortinet FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through 7.6.6, 7.4.1 t…
CVE-2026-24640 CVSS 6.6 fortiweb
CVE-2026-24640 is a medium severity (CVSS 6.6) stack-based buffer overflow vulnerability affecting Fortinet FortiWeb versions 8.0.0 through 8.0.2, 7.6.0 through…
CVE-2026-30897 CVSS 6.6 fortiweb
CVE-2026-30897 is a stack-based buffer overflow (CWE-121) in Fortinet FortiWeb versions 8.0.0-8.0.3, 7.6.0-7.6.6, 7.4.0-7.4.11, 7.2, and 7.0. It allows a remote…
CVE-2025-53847 CVSS 6.5 fortios
CVE-2025-58693 CVSS 6.5 fortivoice
CVE-2026-25689 CVSS 6.5 fortideceptor
CVE-2025-49784 CVSS 6.0 fortianalyzer
CVE-2025-61624 CVSS 6.0 fortios
CVE-2025-68649 CVSS 6.0 fortianalyzer
CVE-2026-39810 CVSS 6.0 forticlientems
CVE-2025-68686 CVSS 5.9 fortios
CVE-2025-55018 CVSS 5.8 fortios
CVE-2026-44279 CVSS 5.5 fortitoken_mobile
CVE-2024-23104 CVSS 5.4 fortivoice
CVE-2025-61886 CVSS 5.4 fortisandbox
CVE-2026-25088 CVSS 5.4 fortindr
CVE-2025-48840 CVSS 5.3 fortiweb
CVE-2025-48840 is a MEDIUM severity authentication bypass vulnerability (CVSS 5.3) affecting Fortinet FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.8…
CVE-2025-67604 CVSS 5.3 fortianalyzer
CVE-2025-67604 is a medium severity vulnerability (CVSS 5.3) affecting Fortinet FortiAnalyzer and FortiManager versions 6.4 through 7.6. It is classified as CWE…
CVE-2026-39811 CVSS 4.9 fortiweb
CVE-2025-53608 CVSS 4.8 fortisandbox
CVE-2026-39812 CVSS 4.8 fortisandbox
CVE-2026-25690 CVSS 4.3 fortideceptor
CVE-2026-25972 CVSS 4.3 fortisiem
CVE-2025-55717 CVSS 4.0 fortivoice

Articles tagged with Fortinet (30)

HIGH
NCSC-2026-0156 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiAuthenticator
NCSC Netherlands · 2026-05-13
HIGH
NCSC-2026-0155 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiSandbox
NCSC Netherlands · 2026-05-13
CRITICAL
Fortinet, Ivanti Patch Critical Vulnerabilities
SecurityWeek · 2026-05-13
CRITICAL
Linux Kernel Vulnerability copy.fail - CVE-2026-31431
Fortinet PSIRT · 2026-05-13
HIGH
Fortinet Products Multiple Vulnerabilities
HKCERT · 2026-05-13
CRITICAL
Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808)
Help Net Security · 2026-04-16
CRITICAL
Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP
The Register Security · 2026-04-15
CRITICAL
NCSC-2026-0121 [1.00] [M/H] Kwetsbaarheden verholpen in Fortinet FortiSandbox
NCSC Netherlands · 2026-04-15
MEDIUM
[NEU] [mittel] Fortinet FortiVoice: Schwachstelle ermöglicht Offenlegung von Informationen
BSI Germany · 2026-04-15
MEDIUM
[NEU] [mittel] Fortinet FortiOS: Schwachstelle ermöglicht Manipulation von Dateien
BSI Germany · 2026-04-15
MEDIUM
[NEU] [mittel] Fortinet FortiOS, FortiProxy und FortiSwitch: Schwachstelle ermöglicht Manipulation von Dateien
BSI Germany · 2026-04-15
CRITICAL
[NEU] [hoch] Fortinet FortiSandbox: Mehrere Schwachstellen
BSI Germany · 2026-04-15
HIGH
[NEU] [hoch] Fortinet FortiAnalyzer und FortiManager: Mehrere Schwachstellen
BSI Germany · 2026-04-15
HIGH
[NEU] [mittel] Fortinet FortiClientEMS: Mehrere Schwachstellen
BSI Germany · 2026-04-15
HIGH
Multiples vulnérabilités dans les produits Fortinet (15 avril 2026)
CERT-FR (ANSSI) · 2026-04-15
MEDIUM
unauthorized backup file access
Fortinet PSIRT · 2026-04-14
CRITICAL
Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox
Fortinet PSIRT · 2026-04-14
MEDIUM
Stored Cross Site Scripting (XSS) in Reports View page
Fortinet PSIRT · 2026-04-14
HIGH
SSRF via Report template and scheduling
Fortinet PSIRT · 2026-04-14
HIGH
Multiple SQL Injections
Fortinet PSIRT · 2026-04-14
CRITICAL
Veikleikar hjá Fortinet, Cisco, Juniper, Adobe og Marimo
CERT-IS · 2026-04-13
CRITICAL
Fortinet FortiClientEMS Remote Code Execution Vulnerability
HKCERT · 2026-04-08
CRITICAL
Fortinet releases emergency hotfix for FortiClient EMS zero-day flaw
CSO Online · 2026-04-07
CRITICAL
Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited
Infosecurity Magazine · 2026-04-07
CRITICAL
Fortinet customers confront actively exploited zero-day, with a full patch still pending
CyberScoop · 2026-04-06
CRITICAL
CISA orders feds to patch exploited Fortinet EMS flaw by Friday
BleepingComputer · 2026-04-06
CRITICAL
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
Tenable Research · 2026-04-06
HIGH
CISA Adds One Known Exploited Vulnerability to Catalog
CISA All Advisories · 2026-04-06
CRITICAL
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
The Hacker News · 2026-04-05
CRITICAL
API authentication and authorization bypass
Fortinet PSIRT · 2026-04-04