Vendor
Fortinet
As of , 31 Fortinet vulnerabilities are on CISA's list of exploited vulnerabilities, 14 of them used in ransomware campaigns; 8 were added in 2026. Patch first: CVE-2026-25089.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-25089OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.76 | ||
| 2 | CVE-2026-39808OS Command Injection | Fortinet FortiSandbox | Patch nowForensic triage required by CISA | 0.47 | ||
| 3 | CVE-2025-25249Heap-based Buffer Overflow | Fortinet Multiple Products | Patch nowForensic triage required by CISA | 0.04 | ||
| 4 | CVE-2026-104286Path Traversal | Fortinet FortiMail | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.02 | ||
| 5 | CVE-2025-58034OS Command Injection | Fortinet FortiWeb | Patch this weekMetasploit module; EPSS 0.56 | 0.56 | ||
| 6 | CVE-2025-64446Path Traversal | Fortinet FortiWeb | Patch this weekMetasploit module; EPSS 0.92 | 0.92 | ||
| 7 | CVE-2024-47575Missing Authentication | Fortinet FortiManager | Patch this weekMetasploit module; EPSS 0.95 | 0.95 | ||
| 8 | CVE-2023-48788SQL Injection | Fortinet FortiClient EMS | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 9 | CVE-2022-40684Authentication Bypass | Fortinet Multiple Products | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 10 | CVE-2018-13379SSL VPN Path Traversal | Fortinet FortiOS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 11 | CVE-2018-13374Improper Access Control | Fortinet FortiOS and FortiADC | Patch this weekRansomware use; verified Exploit-DB entry | 0.38 | ||
| 12 | CVE-2026-21643SQL Injection | Fortinet FortiClient EMS | Patch this weekEPSS 0.94 | 0.94 | ||
| 13 | CVE-2026-24858Authentication Bypass Using an Alternate Path or Channel | Fortinet Multiple Products | Patch this weekEPSS 0.86 | 0.86 | ||
| 14 | CVE-2025-59718Improper Verification of Cryptographic Signature | Fortinet Multiple Products | Patch this weekEPSS 0.68 | 0.68 | ||
| 15 | CVE-2025-25257SQL Injection | Fortinet FortiWeb | Patch this weekEPSS 0.99 | 0.99 | ||
| 16 | CVE-2024-55591Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 17 | CVE-2024-23113Format String | Fortinet Multiple Products | Patch this weekEPSS 0.62 | 0.62 | ||
| 18 | CVE-2024-21762Out-of-Bound Write | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| 19 | CVE-2023-27997Heap-Based Buffer Overflow | Fortinet FortiOS and FortiProxy SSL-VPN | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 20 | CVE-2022-42475Heap-Based Buffer Overflow | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 21 | CVE-2018-13382Improper Authorization | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 22 | CVE-2018-13383Out-of-bounds Write | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.34 | ||
| 23 | CVE-2020-12812SSL VPN Improper Authentication | Fortinet FortiOS | Patch this weekRansomware use | 0.45 | ||
| 24 | CVE-2019-5591Default Configuration | Fortinet FortiOS | Patch this weekRansomware use | 0.18 | ||
| 25 | CVE-2025-24472Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.07 |
Products
- FortiOS9 entries
- Multiple Products6 entries
- FortiOS and FortiProxy4 entries
- FortiClient EMS3 entries
- FortiWeb3 entries
- FortiSandbox2 entries
- FortiMail1 entry
- FortiManager1 entry
- FortiOS and FortiADC1 entry
- FortiOS and FortiProxy SSL-VPN1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 4 |
| 2022 | 5 |
| 2023 | 2 |
| 2024 | 4 |
| 2025 | 8 |
| 2026 | 8 |