Fortimail
Vendor:
First CVE: Feb 4, 2013 · Active for 13 years
46
Total CVEs
More Total CVEs than 98% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fortimail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2013
13 years ago
Most Recent CVE
May 12, 2026
77 days ago
CVE Severity & Scoring
Fortimail46 CVEs
54%
30%
15%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (13.0%)
Network37 (80.4%)
Unknown3 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low41 (89.1%)
High2 (4.3%)
Unknown3 (6.5%)
User Interaction
None34 (73.9%)
Unknown3 (6.5%)
Required9 (19.6%)
Privileges Required
Low11 (23.9%)
High10 (21.7%)
None22 (47.8%)
Unknown3 (6.5%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32756CRITICAL A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMa | May 13, 2025 | 9.8 | 85 | YES | NO |
CVE-2020-9294CRITICAL An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to acces | Apr 27, 2020 | 9.8 | 80 | NO | YES |
CVE-2021-43062MEDIUM A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and bel | Feb 2, 2022 | 6.1 | 46 | NO | YES |
CVE-2021-36166CRITICAL An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of th | Mar 1, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-32586CRITICAL An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlyi | Mar 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-24007CRITICAL Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code o | Jul 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-47539CRITICAL An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to | Mar 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-24020CRITICAL A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to t | Jul 9, 2021 | 9.8 | 29 | NO | NO |
CVE-2025-53681HIGH An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7 | May 12, 2026 | 7.2 | 27 | NO | NO |
CVE-2022-26122HIGH An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below m | Nov 2, 2022 | 8.6 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
1 CVE
2.2% of CVEs· 98th percentile
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
1 CVE
2.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
4.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Fortimail
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.4.0 | 2 | 8.6 | 0.8% | 0 | 0 |
| 7.2.2 | 2 | 7.1 | 0.6% | 0 | 0 |
| 7.2.1 | 2 | 7.1 | 0.6% | 0 | 0 |
| 7.2.0 | 3 | 6.9 | 0.5% | 0 | 0 |
| 7.0.1 | 1 | 5.3 | 0.9% | 0 | 0 |
| 7.0.0 | 3 | 8.3 | 1.1% | 0 | 0 |
| 6.4.1 | 1 | 5.3 | 0.8% | 0 | 0 |
| 6.4.0 | 2 | 5.3 | 1.3% | 0 | 0 |
| 6.2.4 | 1 | 5.3 | 0.8% | 0 | 0 |
| 6.2.3 | 1 | 5.3 | 0.8% | 0 | 0 |
| 6.2.2 | 1 | 5.3 | 0.8% | 0 | 0 |
| 6.2.1 | 1 | 5.3 | 0.8% | 0 | 0 |
| 6.2.0 | 3 | 5.8 | 1.0% | 0 | 0 |
| 5.3.9 | 1 | 6.1 | 2.1% | 0 | 0 |
| 5.3.8 | 2 | 6.1 | 1.6% | 0 | 0 |
| 5.3.7 | 2 | 6.1 | 1.6% | 0 | 0 |
| 5.3.6 | 2 | 6.1 | 1.6% | 0 | 0 |
| 5.3.5 | 2 | 6.1 | 1.6% | 0 | 0 |
| 5.3.4 | 2 | 6.1 | 1.6% | 0 | 0 |
| 5.3.3 | 2 | 6.1 | 1.6% | 0 | 0 |