Fortiproxy
Vendor:
First CVE: May 29, 2019 · Active for 7 years
125
Total CVEs
More Total CVEs than 99% of tracked products
15.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
9.6%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fortiproxy over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2019
7 years ago
Most Recent CVE
Jul 14, 2026
11 days ago
CVE Severity & Scoring
Fortiproxy125 CVEs
54%
30%
14%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local20 (16.0%)
Network101 (80.8%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network3 (2.4%)
Attack Complexity
Low113 (90.4%)
High12 (9.6%)
Unknown0 (0.0%)
User Interaction
None102 (81.6%)
Unknown0 (0.0%)
Required23 (18.4%)
Privileges Required
Low40 (32.0%)
High29 (23.2%)
None56 (44.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (125 CVEs).
125 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40684CRITICAL An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version | Oct 18, 2022 | 9.8 | 99 | YES | YES |
CVE-2018-13379CRITICAL An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 | Jun 4, 2019 | 9.8 | 99 | YES | YES |
CVE-2024-55591CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7 | Jan 14, 2025 | 9.8 | 98 | YES | YES |
CVE-2022-42475CRITICAL A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier an | Jan 2, 2023 | 9.8 | 98 | YES | YES |
CVE-2026-24858CRITICAL An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, | Jan 27, 2026 | 9.8 | 96 | YES | NO |
CVE-2024-21762CRITICAL A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, | Feb 9, 2024 | 9.8 | 95 | YES | NO |
CVE-2023-27997CRITICAL A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy | Jun 13, 2023 | 9.8 | 95 | YES | NO |
CVE-2018-13382HIGH An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 | Jun 4, 2019 | 7.5 | 95 | YES | YES |
CVE-2025-59718CRITICAL A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t | Dec 9, 2025 | 9.8 | 94 | YES | NO |
CVE-2024-23113CRITICAL A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7 | Feb 15, 2024 | 9.8 | 92 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (125 CVEs).
CISA KEV
12 CVEs
9.6% of CVEs· 97th percentile
Metasploit
2 CVEs
1.6% of CVEs· 96th percentile
Nuclei
5 CVEs
4.0% of CVEs· 97th percentile
ExploitDB
3 CVEs
2.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (125 CVEs).
Media Mentions
Signals from CVEs in this product scope (125 CVEs).
Top CNAs Publishing CVEs For Fortiproxy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6.0 | 3 | 7.2 | 0.7% | 0 | 0 |
| 7.4.1 | 2 | 6.9 | 0.6% | 0 | 0 |
| 7.4.0 | 5 | 7.7 | 1.2% | 0 | 0 |
| 7.2.3 | 1 | 4.3 | 0.9% | 0 | 0 |
| 7.2.2 | 4 | 6.8 | 1.1% | 0 | 0 |
| 7.2.1 | 13 | 6.2 | 0.6% | 0 | 0 |
| 7.2.0 | 15 | 6.5 | 7.3% | 1 | 1 |
| 7.0.1 | 2 | 7.3 | 0.3% | 0 | 0 |
| 7.0.0 | 4 | 6.6 | 0.7% | 0 | 0 |
| 2.0.1 | 2 | 7.0 | 0.7% | 0 | 0 |
| 2.0.0 | 11 | 6.9 | 25.8% | 3 | 3 |
| 1.2.0 | 1 | 8.8 | 0.9% | 0 | 0 |
| 1.1.6 | 1 | 6.5 | 0.8% | 0 | 0 |
| 1.1.5 | 1 | 6.5 | 0.8% | 0 | 0 |
| 1.1.0 | 1 | 8.8 | 0.9% | 0 | 0 |
| 1.0.0 | 1 | 8.8 | 0.9% | 0 | 0 |