Skip to main content

FortiOS vulnerabilities

7 published alerts for Fortinet FortiOS.

Actively exploited (KEV)

CVE-2025-68686

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-68686). Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. CISA remediation due date: 2026-08-10. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-6693

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-6693). Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. CISA remediation due date: 2025-07-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21762

Fortinet FortiOS Out-of-Bound Write Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21762). Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests. CISA remediation due date: 2024-02-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-42475

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-42475). Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. CISA remediation due date: 2023-01-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-12812

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12812). Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-5591

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-5591). Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-13379

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-13379). Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.