Fortinet FortiOS
Our sources currently list 277 known vulnerabilities affecting Fortinet FortiOS. 22 are rated critical severity. 18 of 277 are actively exploited according to CISA, the most recent added 27 January 2026.
Last updated: 22 July 2026, 20:32 AEST
Australian advisories
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2018-13379 | Critical (9.1) | Actively exploited · ransomware | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0… | |
| CVE-2022-40684 | Critical (9.8) | Actively exploited · ransomware | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version … | |
| CVE-2022-42475 | Critical (9.8) | Actively exploited · ransomware | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an… | |
| CVE-2024-55591 | Critical (9.8) | Actively exploited · ransomware | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7… | |
| CVE-2026-24858 | Critical (9.8) | Actively exploited | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, … | |
| CVE-2023-27997 | Critical (9.8) | Actively exploited · ransomware | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy… | |
| CVE-2024-21762 | Critical (9.8) | Actively exploited · ransomware | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17,… | |
| CVE-2018-13382 | Critical (9.1) | Actively exploited · ransomware | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 … | |
| CVE-2025-59718 | Critical (9.8) | Actively exploited | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t… | |
| CVE-2024-23113 | Critical (9.8) | Actively exploited | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7… | |
| CVE-2020-12812 | Critical (9.8) | Actively exploited · ransomware | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted … | |
| CVE-2018-13374 | Medium (4.3) | Actively exploited · ransomware | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials co… | |
| CVE-2018-13383 | Medium (4.3) | Actively exploited · ransomware | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VP… | |
| CVE-2019-5591 | Medium (6.5) | Actively exploited | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server. | |
| CVE-2022-41328 | Medium (6.7) | Actively exploited | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and bef… | |
| CVE-2019-6693 | Medium (6.5) | Actively exploited · ransomware | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive d… | |
| CVE-2025-24472 | High (8.1) | Actively exploited · ransomware | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19… | |
| CVE-2021-44168 | Low (3.3) | Actively exploited | A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbit… | |
| CVE-2016-1909 | Critical (9.8) | Elevated likelihood (71%) | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.… | |
| CVE-2018-13380 | Medium (4.7) | Elevated likelihood (62%) | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under S… | |
| CVE-2016-6909 | Critical (9.8) | Elevated likelihood (50%) | Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to exec… | |
| CVE-2022-38380 | Medium (4.3) | Elevated likelihood (23%) | An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a remote authenticated read-only user to modify the interface… | |
| CVE-2023-25610 | Critical (9.8) | Elevated likelihood (18%) | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t… | |
| CVE-2024-48884 | High (7.5) | Elevated likelihood (15%) | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, Forti… | |
| CVE-2015-1880 | Medium (4.3) | Elevated likelihood (14%) | Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecif… | |
| CVE-2017-3133 | Medium (6.1) | Elevated likelihood (11%) | A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for S… | |
| CVE-2017-3132 | Medium (6.1) | No exploitation reported | A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activa… | |
| CVE-2017-3131 | Medium (5.4) | No exploitation reported | A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "A… | |
| CVE-2016-3978 | Medium (6.1) | No exploitation reported | The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and condu… | |
| CVE-2014-2216 | High (7.5) | No exploitation reported | The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly ex… | |
| CVE-2017-14186 | Medium (5.4) | No exploitation reported | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitr… | |
| CVE-2024-21754 | Low (1.8) | No exploitation reported | A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all version… | |
| CVE-2015-7361 | Critical (9.3) | No exploitation reported | FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the… | |
| CVE-2023-42789 | Critical (9.8) | No exploitation reported | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 … | |
| CVE-2005-3058 | High (7.5) | No exploitation reported | Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a l… | |
| CVE-2005-3057 | Critical (10.0) | No exploitation reported | The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by se… | |
| CVE-2023-29180 | High (7.5) | No exploitation reported | A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0… | |
| CVE-2023-29179 | Medium (6.5) | No exploitation reported | A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10… | |
| CVE-2013-7182 | Medium (4.3) | No exploitation reported | Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parame… | |
| CVE-2013-1414 | Medium (5.1) | No exploitation reported | Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the… | |
| CVE-2018-9185 | High (8.1) | No exploitation reported | An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages… | |
| CVE-2023-33308 | Critical (9.8) | No exploitation reported | A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through… | |
| CVE-2018-13376 | High (7.5) | No exploitation reported | An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing… | |
| CVE-2015-5965 | Medium (5.0) | No exploitation reported | The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted … | |
| CVE-2005-4570 | High (7.8) | No exploitation reported | The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause … | |
| CVE-2021-26109 | High (8.1) | No exploitation reported | An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap … | |
| CVE-2015-1452 | High (7.8) | No exploitation reported | The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWA… | |
| CVE-2014-8616 | Medium (4.3) | No exploitation reported | Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.2.x before 5.2.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to … | |
| CVE-2019-15705 | High (7.5) | No exploitation reported | An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the … | |
| CVE-2006-3222 | Medium (5.0) | No exploitation reported | The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode. |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
18 of these are being actively exploited right now.
Our Newcastle team can audit your Fortinet estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
