Perimeter Security & Firewalls10 Active Advisories Tracked

Fortinet Vulnerability & Threat Radar

Zero-day tracking and CISA KEV catalog additions impacting Fortinet FortiOS, FortiGate firewalls, and FortiClient endpoints.

Recommended Protective Controls for Fortinet Environments

Deploy continuous behavioral telemetry and micro-segmentation boundaries to shield Fortinet assets.

Evaluate Recommended Defenses →

Recent Disclosures & Advisories

10 Critical Severity
CISA KEV
11d ago

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. This is a critical threat mapped to CVE-2025-25249; security leaders should validate exposure, prioritize patching, an...

CISA KEV
7/16/2026

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. This is a critical threat mapped to CVE-2026-25089; security leaders should validate exposure...

CISA KEV
7/16/2026

Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. This is a critical threat mapped to CVE-2026-39808; security leaders should validate exposure, prioritize patching, and verify compensa...

CISA KEV
4/13/2026

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. This is a critical threat mapped to CVE-2026-21643; security leaders should validate exposure, prioritize patching, and verify co...

CISA KEV
4/6/2026

Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. This is a critical threat mapped to CVE-2026-35616; security leaders should validate exposure, prioritize patching, and verify compensat...

CISA KEV
1/27/2026

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those...

CISA KEV
12/16/2025

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. This is a critical threat mapped to CVE-2025-59719, CVE-2025...

CISA KEV
11/18/2025

Fortinet FortiWeb OS Command Injection Vulnerability

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands. This is a critical threat mapped to CVE-2025-58034; security leaders should validate exposure, prioritize patching...

CISA KEV
11/14/2025

Fortinet FortiWeb Path Traversal Vulnerability

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests. This is a critical threat mapped to CVE-2025-64446; security leaders should validate exposure, prioritize patching, and ve...

Share Intel:Share on XLinkedIn

Never Miss a Critical Fortinet Patch

Subscribe to the SecOps Pulse executive threat briefing for early warnings on unpatched vulnerabilities.

Weekly Executive Briefing

Top critical & high-severity threats, every week.

No spam. Unsubscribe anytime. SecOpsPulse may include sponsored security tool recommendations.