fortinet has 62 CVEs on record between 2019 and 2026. Disclosure cadence is accelerating: 20 in the last 90 days against 7 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 7.0 (medium), with 14 rated critical. 21% have been exploited in the wild — well above the 1% corpus average, so fortinet flaws are worth patching on sight. The median gap from publication to a KEV listing is 130 days (12 cases). The dominant weakness classes are CWE-78 (5) and CWE-787 (5). Most affected products: fortiproxy (12), FortiOS (10), FortiAnalyzer (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 21% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- 130 d median(12)
- Last 90 days
- 20 prev 7
Products
- fortiproxy 12
- FortiOS 10
- FortiAnalyzer 6
- FortiSandbox 4
- fortiweb 4
- fortiwebmanager 4
Worst active — by depth score
CVE-2024-55591Critical· 9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…100CVE-2024-21762Critical· 9.8A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…100CVE-2023-27997Critical· 9.8A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…100CVE-2022-40684Critical· 9.8An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …100CVE-2026-25089Critical· 9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …94
fortinet vulnerabilities
CVEs affecting fortinet, newest first. Open any entry for full detail, references, and exploit status.
62 CVEsRSS
CVE-2019-6693Medium· 6.5CISA KEVPoCUse of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementio…
CVE-2018-13374Medium· 4.3CISA KEVPoCA Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connecti…
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connecti…