Fortinet Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Fortinet products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
34
In CISA KEV
29
Beyond CISA KEV
5
Sensor Observed
3
Virtual Patch Available
2
Fortinet KEVs Added by Year
34 Fortinet KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-68686
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,... |
FortiOS | Confirmed | In CISA | 27 Jul 2026 |
|
CVE-2026-25089
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through... |
FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS | Confirmed | In CISA | 16 Jul 2026 |
|
CVE-2026-39813
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to... |
FortiSandbox, FortiSandbox Cloud | Confirmed | Not in CISA | 15 Jun 2026 |
|
CVE-2026-39808
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through... |
FortiSandbox, FortiSandbox PaaS | Confirmed | In CISA | 12 Jun 2026 |
|
CVE-2021-22122
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an... |
Fortinet FortiWeb | High | Not in CISA | 28 Dec 2025 |
|
CVE-2023-34993
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and... |
FortiWLM | High | Not in CISA | 29 Jul 2025 |
|
CVE-2026-21643
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an... |
FortiClientEMS | Confirmed | In CISA | 28 May 2026 |
|
CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute... |
FortiClientEMS | Confirmed | In CISA | 28 May 2026 |
|
CVE-2026-25815
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from... |
FortiOS | High | Not in CISA | 01 Jun 2026 |
|
CVE-2026-24858
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5,... |
FortiWeb, FortiNAC-F, FortiOS, FortiAnalyzer, FortiProxy, FortiManager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-59718
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS... |
FortiSwitchManager, FortiOS, FortiProxy | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-58034
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet... |
FortiWeb | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9,... |
FortiWeb | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions,... |
FortiNDR, FortiCamera, FortiRecorder, FortiVoice, FortiMail | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-25257
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb... |
FortiWeb | Confirmed | In CISA | 28 May 2026 |
|
CVE-2019-6693
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup... |
FortiGate | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-39952
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0... |
FortiNAC | High | Not in CISA | 23 Apr 2025 |
|
CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to... |
Fortinet FortiOS, FortiProxy | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-12812
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in... |
Fortinet FortiOS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-5591
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by... |
Fortinet FortiOS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-44168
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local... |
Fortinet FortiOS | Confirmed | In CISA | 10 Dec 2021 |
|
CVE-2018-13383
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy... |
Fortinet FortiOS and FortiProxy | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to... |
Fortinet FortiOS, FortiProxy | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2018-13374
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the... |
Fortinet FortiOS, fortiADC | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,... |
Fortinet FortiOS, FortiProxy, FortiSwitchManager | Confirmed | In CISA | 11 Oct 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 3
- CWE-288 — Authentication Bypass Using an Alternate Path or Channel 3
- CWE-787 — Out-of-bounds Write 2
- CWE-306 — Missing Authentication for Critical Function 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-287 — Improper Authentication 2
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology