Fortinet FortiOS

Our sources currently list 277 known vulnerabilities affecting Fortinet FortiOS. 22 are rated critical severity. 18 of 277 are actively exploited according to CISA, the most recent added 27 January 2026.

Last updated: 22 July 2026, 20:32 AEST

ASD’s ACSC CRITICAL alert

Reported widespread credential exposure affecting Fortinet Firewalls and VPN Gateways

Published 2026-06-18 by the Australian Signals Directorate’s Australian Cyber Security Centre

ASD’s ACSC advisory

Critical vulnerabilities in multiple Fortinet products - FortiCloud SSO Login Authentication Bypass

Published 2025-12-10 by the Australian Signals Directorate’s Australian Cyber Security Centre · references CVE-2025-59718

Known vulnerabilities in Fortinet FortiOS, highest risk first.Showing the 50 highest-risk of 277 total.
CVESeverityExploitationPublishedSummary
CVE-2018-13379Critical (9.1)Actively exploited · ransomwareAn Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0…
CVE-2022-40684Critical (9.8)Actively exploited · ransomwareAn authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version …
CVE-2022-42475Critical (9.8)Actively exploited · ransomwareA heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an…
CVE-2024-55591Critical (9.8)Actively exploited · ransomwareAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7…
CVE-2026-24858Critical (9.8)Actively exploitedAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, …
CVE-2023-27997Critical (9.8)Actively exploited · ransomwareA heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy…
CVE-2024-21762Critical (9.8)Actively exploited · ransomwareA out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17,…
CVE-2018-13382Critical (9.1)Actively exploited · ransomwareAn Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 …
CVE-2025-59718Critical (9.8)Actively exploitedA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t…
CVE-2024-23113Critical (9.8)Actively exploitedA use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7…
CVE-2020-12812Critical (9.8)Actively exploited · ransomwareAn improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted …
CVE-2018-13374Medium (4.3)Actively exploited · ransomwareA Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials co…
CVE-2018-13383Medium (4.3)Actively exploited · ransomwareA heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VP…
CVE-2019-5591Medium (6.5)Actively exploitedA Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2022-41328Medium (6.7)Actively exploitedA improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and bef…
CVE-2019-6693Medium (6.5)Actively exploited · ransomwareUse of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive d…
CVE-2025-24472High (8.1)Actively exploited · ransomwareAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19…
CVE-2021-44168Low (3.3)Actively exploitedA download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbit…
CVE-2016-1909Critical (9.8)Elevated likelihood (71%)Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.…
CVE-2018-13380Medium (4.7)Elevated likelihood (62%)A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under S…
CVE-2016-6909Critical (9.8)Elevated likelihood (50%)Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to exec…
CVE-2022-38380Medium (4.3)Elevated likelihood (23%)An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface…
CVE-2023-25610Critical (9.8)Elevated likelihood (18%)A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t…
CVE-2024-48884High (7.5)Elevated likelihood (15%)A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, Forti…
CVE-2015-1880Medium (4.3)Elevated likelihood (14%)Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecif…
CVE-2017-3133Medium (6.1)Elevated likelihood (11%)A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for S…
CVE-2017-3132Medium (6.1)No exploitation reportedA Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activa…
CVE-2017-3131Medium (5.4)No exploitation reportedA Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "A…
CVE-2016-3978Medium (6.1)No exploitation reportedThe Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and condu…
CVE-2014-2216High (7.5)No exploitation reportedThe FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly ex…
CVE-2017-14186Medium (5.4)No exploitation reportedA Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitr…
CVE-2024-21754Low (1.8)No exploitation reportedA use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all version…
CVE-2015-7361Critical (9.3)No exploitation reportedFortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the…
CVE-2023-42789Critical (9.8)No exploitation reportedA out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 …
CVE-2005-3058High (7.5)No exploitation reportedInterpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a l…
CVE-2005-3057Critical (10.0)No exploitation reportedThe FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by se…
CVE-2023-29180High (7.5)No exploitation reportedA null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0…
CVE-2023-29179Medium (6.5)No exploitation reportedA null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10…
CVE-2013-7182Medium (4.3)No exploitation reportedCross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parame…
CVE-2013-1414Medium (5.1)No exploitation reportedMultiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the…
CVE-2018-9185High (8.1)No exploitation reportedAn information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages…
CVE-2023-33308Critical (9.8)No exploitation reportedA stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through…
CVE-2018-13376High (7.5)No exploitation reportedAn uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing…
CVE-2015-5965Medium (5.0)No exploitation reportedThe SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted …
CVE-2005-4570High (7.8)No exploitation reportedThe Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause …
CVE-2021-26109High (8.1)No exploitation reportedAn integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap …
CVE-2015-1452High (7.8)No exploitation reportedThe Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWA…
CVE-2014-8616Medium (4.3)No exploitation reportedMultiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to …
CVE-2019-15705High (7.5)No exploitation reportedAn Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the …
CVE-2006-3222Medium (5.0)No exploitation reportedThe FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

18 of these are being actively exploited right now.

Our Newcastle team can audit your Fortinet estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.