Multiple Products vulnerabilities
3 published alerts for Fortinet Multiple Products.
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-24858). Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices. CISA remediation due date: 2026-01-30. If you need help checking exposure, call (864) 335-9223.
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-59718). Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory. CISA remediation due date: 2025-12-23. If you need help checking exposure, call (864) 335-9223.
Fortinet Multiple Products Authentication Bypass Vulnerability
Fortinet Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-40684). Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. CISA remediation due date: 2022-11-01. If you need help checking exposure, call (864) 335-9223.