Exploitation reported elsewhere › Fortinet
CVE-2025-61624
Exploitation reported by CERT-FR — not (yet) in CISA’s catalog
In brief
Level of evidence: CISA has not (yet) added it to its catalog of exploited vulnerabilities. The report comes from another official source, cited below.
First reported: April 15, 2026.
Brand and category: the site’s indicative classification, based on the vendor name given by CERT-FR.
Who reports it
- Reported by CERT-FR CERT-FR advisory CERTFR-2026-AVI-0440 of April 15, 2026 : Multiples vulnérabilités dans les produits Fortinet
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
What should I do?
Check whether you use this product. If so, apply the fix or workaround given by the vendor, first on devices exposed to the Internet.
Read the CERT-FR publication for affected versions and measures (in French).
If CISA adds it to its catalog, it will join the patch list with its instruction.
- CERT-FR advisory CERTFR-2026-AVI-0440 of April 15, 2026
- Fortinet security advisories page (general page, not the advisory for this vulnerability)
- The vendor’s specific advisory is listed in the NVD references: CVE-2025-61624 on the NVD website.
Severity and activity
Vulnerability published: April 14, 2026.
Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.
Official description from the NVD, collected Oct 4, 2026. CVE® description © The MITRE Corporation.
Sources for this page
- CERT-FR: advisories and alerts (in French).
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- CISA KEV catalog: the vulnerability is not (yet) in it.
- Brand and category: indicative classification by this site (method).