Fortios

Vendor:

First CVE: Dec 31, 2005 · Active for 20 years

277
Total CVEs
More Total CVEs than 100% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fortios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
13 days ago

CVE Severity & Scoring

Fortios277 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local38 (13.7%)
Network209 (75.5%)
Unknown17 (6.1%)
Physical2 (0.7%)
Adjacent Network11 (4.0%)
Attack Complexity
Low225 (81.2%)
High35 (12.6%)
Unknown17 (6.1%)
User Interaction
None209 (75.5%)
Unknown17 (6.1%)
Required51 (18.4%)
Privileges Required
Low82 (29.6%)
High47 (17.0%)
None131 (47.3%)
Unknown17 (6.1%)

Top CVEs

Signals from CVEs in this product scope (277 CVEs).

277 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version
Oct 18, 20229.899YESYES
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0
Jun 4, 20199.899YESYES
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7
Jan 14, 20259.898YESYES
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an
Jan 2, 20239.898YESYES
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9,
Jan 27, 20269.896YESNO
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17,
Feb 9, 20249.895YESNO
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy
Jun 13, 20239.895YESNO
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
Jun 4, 20197.595YESYES
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t
Dec 9, 20259.894YESNO
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7
Feb 15, 20249.892YESNO

Exploit Exposure

Signals from CVEs in this product scope (277 CVEs).

CISA KEV
18 CVEs
6.5% of CVEs· 98th percentile
Metasploit
3 CVEs
1.1% of CVEs· 97th percentile
Nuclei
12 CVEs
4.3% of CVEs· 97th percentile
ExploitDB
12 CVEs
4.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (277 CVEs).

Media Mentions

Signals from CVEs in this product scope (277 CVEs).

Top CNAs Publishing CVEs For Fortios

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.6.117.20.3%00
7.6.0175.91.4%01
7.4.414.40.1%00
7.4.167.21.2%00
7.4.0127.20.9%00
7.2.714.40.1%00
7.2.518.80.9%00
7.2.226.80.7%00
7.2.137.80.8%00
7.2.0146.32.2%00
7.0.529.343.4%10
7.0.418.81.1%00
7.0.318.81.1%00
7.0.226.50.7%00
7.0.1414.40.1%00
7.0.1019.885.7%10
7.0.147.31.1%00
7.0.0127.30.8%00
6.4.819.885.7%10
6.4.714.30.4%00