Skip to content
English

Products › Brands

Brand

Fortinet: actively exploited vulnerabilities

30 vulnerabilities in Fortinet products (FortiOS / FortiProxy (FortiGate), FortiClient EMS, FortiWeb…) are in CISA’s catalog of exploited vulnerabilities, 4 of them added in the last 90 days. Last added: September 9, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Fortinet category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • FortiOS / FortiProxy (FortiGate) 20 vulnerabilities · Firewalls and VPNs
  • FortiClient EMS 3 vulnerabilities · Monitoring and ITSM
  • FortiWeb 3 vulnerabilities · ADCs
  • FortiSandbox 2 vulnerabilities · Security products
  • FortiManager / FortiAnalyzer 1 vulnerability · Firewalls and VPNs
  • FortiVoice / FortiFone 1 vulnerability · Collaboration and video

Name used by CISA: Fortinet. Product families: indicative classification by this site.

Pace of additions

Number of Fortinet vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20252
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20262
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20263
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)1

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Fortinet list.

  1. Rank 1Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-25249

    Recently addedHunt for compromise (CISA)

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Fortinet FortiSandbox

    CVE-2026-25089

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Fortinet FortiSandbox

    CVE-2026-39808

    Hunt for compromise (CISA)

    Fortinet FortiSandbox OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Fortinet FortiClient EMS

    CVE-2026-21643

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Fortinet FortiClient EMS

    CVE-2026-35616

    Fortinet FortiClient EMS Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 6, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2026-24858

    Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-59718

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 16, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Fortinet FortiWeb

    CVE-2025-64446

    Fortinet FortiWeb Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Fortinet FortiWeb

    CVE-2025-58034

    Fortinet FortiWeb OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 18, 2025
    CISA deadline
    7 days
    CVSS severity
    7.2 (high)
  10. Rank 10Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-68686

    Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 27, 2026
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
Show 20 more vulnerabilities
  1. Rank 11Fortinet FortiWeb

    CVE-2025-25257

    Fortinet FortiWeb SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Fortinet FortiVoice / FortiFone

    CVE-2025-32756

    Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-55591

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Fortinet FortiManager / FortiAnalyzer

    CVE-2024-47575

    Fortinet FortiManager Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-23113

    Fortinet Multiple Products Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Fortinet FortiClient EMS

    CVE-2023-48788

    Ransomware

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-21762

    Ransomware

    Fortinet FortiOS Out-of-Bound Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 9, 2024
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2023-27997

    Ransomware

    Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-42475

    Ransomware

    Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-40684

    Ransomware

    Fortinet Multiple Products Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13379

    RansomwareCVE from 2018, added in 2021

    Fortinet FortiOS SSL VPN Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2020-12812

    Ransomware

    Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-24472

    Ransomware

    Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 18, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  14. Rank 24Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2021-44168

    Fortinet FortiOS Arbitrary File Download

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  15. Rank 25Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13382

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Improper Authorization

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  16. Rank 26Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2022-41328

    Fortinet FortiOS Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  17. Rank 27Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-6693

    RansomwareCVE from 2019, added in 2025

    Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  18. Rank 28Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13383

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiProxy Out-of-bounds Write

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  19. Rank 29Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2019-5591

    RansomwareCVE from 2019, added in 2021

    Fortinet FortiOS Default Configuration Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  20. Rank 30Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13374

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)

Follow and verify

Get new Fortinet vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.