Fortinet, Inc. maintains a broadly represented portfolio of network security and infrastructure appliances, including firewalls, web application firewalls, proxies, and centralized management and analytics platforms, deployed widely across enterprise perimeter defense and threat monitoring operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and they recur across flagship products such as FortiOS, FortiWeb, FortiProxy, FortiManager, and FortiAnalyzer. The exposure concentrates in weakness classes characteristic of security appliances that parse and process untrusted network traffic: cross-site scripting, OS command injection, path traversal, and sensitive information disclosure, alongside categories that reflect the scope and complexity of platform logic. Because these products are positioned at security boundaries and are often internet-facing or trusted to make access decisions, vulnerabilities here carry outsized operational risk and warrant prioritized monitoring and patching. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fortinet, Inc. over time
Of all the CVEs published by Fortinet, Inc. as a CNA, 98.8% affect products that Fortinet, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Fortinet, Inc., 89.4% are self-published by Fortinet, Inc. as a CNA.
Signals from CVEs in this vendor scope (1137 CVEs).
1,137 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64446CRITICAL A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe | Nov 14, 2025 | 9.8 | 99 | YES | YES |
CVE-2022-40684CRITICAL An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version | Oct 18, 2022 | 9.8 | 99 | YES | YES |
CVE-2018-13379CRITICAL An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 | Jun 4, 2019 | 9.8 | 99 | YES | YES |
CVE-2026-39808CRITICAL A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execut | Apr 14, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-35616CRITICAL A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re | Apr 4, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-21643CRITICAL An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to exec | Feb 6, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-25257CRITICAL An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4. | Jul 17, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-55591CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7 | Jan 14, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-47575CRITICAL A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiMa | Oct 23, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-48788CRITICAL A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 a | Mar 12, 2024 | 9.8 | 98 | YES | YES |
Signals from CVEs in this vendor scope (1137 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fortinet, Inc..
Media articles that mention a CVE ID that affects a product developed by Fortinet, Inc. — matched by CVE ID, not by vendor name.