Fortinet FortiManager
Our sources currently list 111 known vulnerabilities affecting Fortinet FortiManager. 6 are rated critical severity. 2 of 111 are actively exploited according to CISA, the most recent added 27 January 2026.
Last updated: 22 July 2026, 20:33 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2024-47575 | Critical (9.8) | Actively exploited | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa… | |
| CVE-2026-24858 | Critical (9.8) | Actively exploited | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, … | |
| CVE-2023-25610 | Critical (9.8) | Elevated likelihood (18%) | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t… | |
| CVE-2024-48884 | High (7.5) | Elevated likelihood (15%) | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, Forti… | |
| CVE-2021-32589 | High (8.1) | No exploitation reported | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, versio… | |
| CVE-2015-3611 | High (8.8) | No exploitation reported | A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems… | |
| CVE-2023-42791 | High (8.8) | No exploitation reported | A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker t… | |
| CVE-2021-26104 | High (7.8) | No exploitation reported | Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, Fo… | |
| CVE-2024-23666 | High (7.5) | No exploitation reported | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7… | |
| CVE-2019-17657 | High (7.5) | No exploitation reported | An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below… | |
| CVE-2015-3613 | Critical (9.8) | No exploitation reported | A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page | |
| CVE-2020-9289 | High (7.5) | No exploitation reported | Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access… | |
| CVE-2022-27483 | High (7.2) | No exploitation reported | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.… | |
| CVE-2024-46662 | High (8.8) | No exploitation reported | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 throu… | |
| CVE-2024-40584 | High (7.2) | No exploitation reported | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 th… | |
| CVE-2024-48889 | High (7.2) | No exploitation reported | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version… | |
| CVE-2018-1354 | Medium (6.5) | No exploitation reported | An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avat… | |
| CVE-2018-1355 | Medium (6.1) | No exploitation reported | An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during … | |
| CVE-2023-25607 | High (7.8) | No exploitation reported | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.… | |
| CVE-2023-42787 | Medium (6.5) | No exploitation reported | A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 m… | |
| CVE-2024-36512 | High (7.2) | No exploitation reported | An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 thro… | |
| CVE-2023-42788 | High (7.8) | No exploitation reported | An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 th… | |
| CVE-2024-33502 | Medium (6.5) | No exploitation reported | An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7… | |
| CVE-2023-44256 | Medium (6.5) | No exploitation reported | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version … | |
| CVE-2018-1351 | Medium (4.8) | No exploitation reported | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI c… | |
| CVE-2024-50566 | High (7.2) | No exploitation reported | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.… | |
| CVE-2024-32115 | Medium (5.5) | No exploitation reported | A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underl… | |
| CVE-2021-24006 | Medium (6.3) | No exploitation reported | An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrato… | |
| CVE-2022-22300 | Medium (4.3) | No exploitation reported | A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer vers… | |
| CVE-2024-47571 | High (8.1) | No exploitation reported | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. | |
| CVE-2023-44249 | Medium (4.3) | No exploitation reported | An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3… | |
| CVE-2025-54820 | High (8.1) | No exploitation reported | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions m… | |
| CVE-2018-1360 | High (8.1) | No exploitation reported | A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the … | |
| CVE-2024-32117 | Medium (4.9) | No exploitation reported | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, Forti… | |
| CVE-2024-35275 | Medium (6.6) | No exploitation reported | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4… | |
| CVE-2020-12811 | Medium (6.1) | No exploitation reported | An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an att… | |
| CVE-2015-3612 | Medium (5.4) | No exploitation reported | A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page. | |
| CVE-2021-32598 | Medium (4.3) | No exploitation reported | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below… | |
| CVE-2019-6695 | Critical (9.8) | No exploitation reported | Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recrea… | |
| CVE-2023-36554 | High (8.1) | No exploitation reported | A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows a… | |
| CVE-2022-26121 | Low (3.7) | No exploitation reported | An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6… | |
| CVE-2024-35277 | High (8.6) | No exploitation reported | A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.… | |
| CVE-2018-1353 | Medium (4.3) | No exploitation reported | An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated… | |
| CVE-2022-39950 | High (8.0) | No exploitation reported | An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through… | |
| CVE-2023-44253 | Medium (5.0) | No exploitation reported | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7… | |
| CVE-2021-32603 | High (8.8) | No exploitation reported | A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may a… | |
| CVE-2024-35273 | High (7.2) | No exploitation reported | A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially craft… | |
| CVE-2018-13375 | Medium (6.1) | No exploitation reported | An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing… | |
| CVE-2021-32587 | Medium (4.3) | No exploitation reported | An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a rem… | |
| CVE-2024-32118 | Medium (6.7) | No exploitation reported | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 an… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
2 of these are being actively exploited right now.
Our Newcastle team can audit your Fortinet estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
