Fortios
Vendor:
First CVE: Dec 31, 2005 · Active for 20 years
277
Total CVEs
More Total CVEs than 100% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
6.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fortios over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jul 14, 2026
13 days ago
CVE Severity & Scoring
Fortios277 CVEs
56%
32%
8%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local38 (13.7%)
Network209 (75.5%)
Unknown17 (6.1%)
Physical2 (0.7%)
Adjacent Network11 (4.0%)
Attack Complexity
Low225 (81.2%)
High35 (12.6%)
Unknown17 (6.1%)
User Interaction
None209 (75.5%)
Unknown17 (6.1%)
Required51 (18.4%)
Privileges Required
Low82 (29.6%)
High47 (17.0%)
None131 (47.3%)
Unknown17 (6.1%)
Top CVEs
Signals from CVEs in this product scope (277 CVEs).
277 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40684CRITICAL An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version | Oct 18, 2022 | 9.8 | 99 | YES | YES |
CVE-2018-13379CRITICAL An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 | Jun 4, 2019 | 9.8 | 99 | YES | YES |
CVE-2024-55591CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7 | Jan 14, 2025 | 9.8 | 98 | YES | YES |
CVE-2022-42475CRITICAL A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an | Jan 2, 2023 | 9.8 | 98 | YES | YES |
CVE-2026-24858CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, | Jan 27, 2026 | 9.8 | 96 | YES | NO |
CVE-2024-21762CRITICAL A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, | Feb 9, 2024 | 9.8 | 95 | YES | NO |
CVE-2023-27997CRITICAL A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy | Jun 13, 2023 | 9.8 | 95 | YES | NO |
CVE-2018-13382HIGH An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 | Jun 4, 2019 | 7.5 | 95 | YES | YES |
CVE-2025-59718CRITICAL A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t | Dec 9, 2025 | 9.8 | 94 | YES | NO |
CVE-2024-23113CRITICAL A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7 | Feb 15, 2024 | 9.8 | 92 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (277 CVEs).
CISA KEV
18 CVEs
6.5% of CVEs· 98th percentile
Metasploit
3 CVEs
1.1% of CVEs· 97th percentile
Nuclei
12 CVEs
4.3% of CVEs· 97th percentile
ExploitDB
12 CVEs
4.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (277 CVEs).
Media Mentions
Signals from CVEs in this product scope (277 CVEs).
Top CNAs Publishing CVEs For Fortios
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6.1 | 1 | 7.2 | 0.3% | 0 | 0 |
| 7.6.0 | 17 | 5.9 | 1.4% | 0 | 1 |
| 7.4.4 | 1 | 4.4 | 0.1% | 0 | 0 |
| 7.4.1 | 6 | 7.2 | 1.2% | 0 | 0 |
| 7.4.0 | 12 | 7.2 | 0.9% | 0 | 0 |
| 7.2.7 | 1 | 4.4 | 0.1% | 0 | 0 |
| 7.2.5 | 1 | 8.8 | 0.9% | 0 | 0 |
| 7.2.2 | 2 | 6.8 | 0.7% | 0 | 0 |
| 7.2.1 | 3 | 7.8 | 0.8% | 0 | 0 |
| 7.2.0 | 14 | 6.3 | 2.2% | 0 | 0 |
| 7.0.5 | 2 | 9.3 | 43.4% | 1 | 0 |
| 7.0.4 | 1 | 8.8 | 1.1% | 0 | 0 |
| 7.0.3 | 1 | 8.8 | 1.1% | 0 | 0 |
| 7.0.2 | 2 | 6.5 | 0.7% | 0 | 0 |
| 7.0.14 | 1 | 4.4 | 0.1% | 0 | 0 |
| 7.0.10 | 1 | 9.8 | 85.7% | 1 | 0 |
| 7.0.1 | 4 | 7.3 | 1.1% | 0 | 0 |
| 7.0.0 | 12 | 7.3 | 0.8% | 0 | 0 |
| 6.4.8 | 1 | 9.8 | 85.7% | 1 | 0 |
| 6.4.7 | 1 | 4.3 | 0.4% | 0 | 0 |