2 actively exploited
FortiGate 7.6.1: known CVEs & fixed releases
29 CVEs affect this build · 2 in CISA KEV (actively exploited) · highest CVSS 9.8 · 5 builds behind the latest 7.6.6 · updated 2026-06-26
Patch path: upgrade to 6.4.16 or 6.4.17 or 7.0.17 or 7.0.18 or 7.2.11 or 7.2.12 or 7.4.10 or 7.4.11 or 7.4.6 or 7.4.7 or 7.4.8 or 7.4.9 or 7.6.2 or 7.6.3 or 7.6.4 or 7.6.5 or 7.6.6 to clear the exploited issues below.
- KEV · exploited CRITICALCVE-2026-24858
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
- CVSS
- 9.8
- EPSS
- 86%
- KEV added
- 2026-01-27
- Published
- 2026-01-27
Fixed in7.4.11,7.6.6NVD ↗fortiguard.fortinet.com ↗fortinet.com ↗CISA ↗ - KEV · exploited CRITICALCVE-2025-59718
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
- CVSS
- 9.8
- EPSS
- 66%
- KEV added
- 2025-12-16
- Published
- 2025-12-09
Fixed in7.0.18,7.2.12,7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗CISA ↗arcticwolf.com ↗ - MEDIUMCVE-2025-67862
CVE-2025-67862
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
- CVSS
- 6.7
- EPSS
- 0%
- Published
- 2026-06-09
Fixed in7.2.11,7.4.8,7.6.3NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2025-54821
CVE-2025-54821
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.
- CVSS
- 6
- EPSS
- 0%
- Published
- 2025-11-18
Fixed in7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - CRITICALCVE-2025-25249
CVE-2025-25249
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
- CVSS
- 9.8
- Published
- 2026-01-13
Fixed in6.4.17,7.0.18,7.2.12,7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-57740
CVE-2025-57740
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.
- CVSS
- 8.8
- Published
- 2025-10-14
Fixed in7.2.11,7.4.8,7.6.3NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-53847
CVE-2025-53847
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
- CVSS
- 8.8
- Published
- 2026-04-14
Fixed in7.0.18,7.2.12,7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-53844
CVE-2025-53844
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
- CVSS
- 8.8
- Published
- 2026-05-12
Fixed in7.2.12,7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2026-22153
CVE-2026-22153
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
- CVSS
- 8.1
- Published
- 2026-02-10
Fixed in7.6.5NVD ↗fortiguard.fortinet.com ↗ - HIGHCVE-2025-25253
CVE-2025-25253
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions and FortiOS version 7.6.2 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions ZTNA proxy may allow an unauthenticated attacker in a man-in-the middle position to intercept and tamper with connections to the ZTNA proxy
- CVSS
- 7.5
- Published
- 2025-10-14
Fixed in7.4.9,7.6.3NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-53843
CVE-2025-53843
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands via specially crafted packets
- CVSS
- 7.5
- Published
- 2025-11-18
Fixed in7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-58413
CVE-2025-58413
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiSASE 25.3.b allows attacker to execute unauthorized code or commands via specially crafted packets
- CVSS
- 7.5
- Published
- 2025-11-18
Fixed in7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2024-52965
CVE-2024-52965
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.
- CVSS
- 7.2
- Published
- 2025-07-08
Fixed in7.0.17,7.2.11,7.4.6NVD ↗fortiguard.fortinet.com ↗ - HIGHCVE-2025-22258
CVE-2025-22258
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.
- CVSS
- 7.2
- Published
- 2025-10-14
Fixed in7.0.17,7.2.11,7.4.7,7.6.3NVD ↗fortiguard.fortinet.com ↗ - HIGHCVE-2025-22254
CVE-2025-22254
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
- CVSS
- 7.2
- Published
- 2025-06-10
Fixed in6.4.16,7.0.17,7.2.11,7.4.7,7.6.2NVD ↗fortiguard.fortinet.com ↗ - HIGHCVE-2025-53744
CVE-2025-53744
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.
- CVSS
- 7.2
- Published
- 2025-08-12
Fixed in7.4.8,7.6.3NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2025-64157
CVE-2025-64157
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.
- CVSS
- 7.2
- Published
- 2026-02-10
Fixed in7.4.10,7.6.5NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - HIGHCVE-2024-50571
CVE-2024-50571
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1 through 7.0.13, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.0 through 7.2.9, FortiManager 7.0.0 through 7.0.13, FortiManager 6.4 all versions, FortiManager 6.2 all versions, FortiManager 6.0 all versions, FortiManager Cloud 7.6.2, FortiManager Cloud 7.4.1 through 7.4.5, FortiManager Cloud 7.2.1 through 7.2.9, FortiManager Cloud 7.0.1 through 7.0.13, FortiManager Cloud 6.4 all versions, FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiOS 6.2 all versions, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiProxy 7.2.0 through 7.2.12, FortiProxy 7.0.0 through 7.0.19, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions allows attacker to execute unauthorized code or commands via specifically crafted requests.
- CVSS
- 7.2
- Published
- 2025-10-14
Fixed in6.4.16,7.0.17,7.2.11,7.4.7,7.6.3NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2025-24477
CVE-2025-24477
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
- CVSS
- 6.7
- Published
- 2025-07-15
Fixed in7.2.12,7.4.8,7.6.3NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2025-24471
CVE-2025-24471
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
- CVSS
- 6.5
- Published
- 2025-06-10
Fixed in7.4.8,7.6.2NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-25248
CVE-2025-25248
An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.
- CVSS
- 6.5
- Published
- 2025-08-12
Fixed in7.2.11,7.4.8,7.6.3NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-61624
CVE-2025-61624
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.
- CVSS
- 6.5
- Published
- 2026-04-14
Fixed in7.4.10,7.6.5NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-25252
CVE-2025-25252
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
- CVSS
- 6.5
- Published
- 2025-10-14
Fixed in7.0.17,7.2.11,7.4.7,7.6.3NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2025-47890
CVE-2025-47890
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
- CVSS
- 6.1
- Published
- 2025-10-14
Fixed in7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-31366
CVE-2025-31366
An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.
- CVSS
- 6.1
- Published
- 2025-10-14
Fixed in7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-68686
CVE-2025-68686
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
- CVSS
- 5.9
- Published
- 2026-02-10
Fixed in7.4.7,7.6.2NVD ↗fortiguard.fortinet.com ↗ - MEDIUMCVE-2025-58903
CVE-2025-58903
An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
- CVSS
- 4.9
- Published
- 2025-10-14
Fixed in7.4.9,7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-31514
CVE-2025-31514
A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>
- CVSS
- 4.3
- Published
- 2025-10-14
Fixed in7.6.4NVD ↗fortiguard.fortinet.com ↗cert-portal.siemens.com ↗ - MEDIUMCVE-2025-25255
CVE-2025-25255
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.
- CVSS
- 4.3
- Published
- 2025-10-14
Fixed in7.6.4NVD ↗fortiguard.fortinet.com ↗
Stop checking versions by hand
Is your whole fleet exposed, not just this FortiGate?
VulnMonitor reconciles every advisory against your real inventory and ranks what matters by actual exploitation (CISA KEV, EPSS), not raw CVSS. New CVE hits your gear, it is on your queue with the fix attached.
Free to start · no credit card
Other FortiGate versions
- 7.2.0 132 CVEs · 7 KEV
- 7.0.3 130 CVEs · 10 KEV
- 7.0.2 130 CVEs · 10 KEV
- 7.0.1 129 CVEs · 10 KEV
- 7.2.2 128 CVEs · 7 KEV
- 7.2.1 128 CVEs · 7 KEV
- 7.0.5 128 CVEs · 9 KEV
- 7.0.4 128 CVEs · 9 KEV
- 7.0.0 126 CVEs · 10 KEV
- 7.0.10 111 CVEs · 7 KEV
- 6.4.8 104 CVEs · 4 KEV
- 6.4.6 102 CVEs · 4 KEV
- 6.4.10 101 CVEs · 3 KEV
- 6.4.1 101 CVEs · 4 KEV