Vendor advisories

Fortinet PSIRT Advisories

Browse 40 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 13 minutes ago Checked every 15 minutes

40 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Fortinet PSIRT AdvisoriesFG-IR-26-168
CriticalCVSS 9.1

Improper Authentication of FortiPAM Server

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious websit...

Affected productsFortiPAM
Fortinet PSIRT AdvisoriesFG-IR-26-174
HighCVSS 7.3

ZTNA Portal Improper Certificate Validation

CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backe...

Affected productsFortiOS, FortiProxy
Fortinet PSIRT AdvisoriesFG-IR-26-166
HighCVSS 8.9

Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Affected productsFortiSandbox, FortiSandbox Cloud
Fortinet PSIRT AdvisoriesFG-IR-26-172
MediumCVSS 5.9

Uncontrolled Resource Consumption in SNMP

CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

Affected productsFortiAnalyzer
Fortinet PSIRT AdvisoriesFG-IR-26-169
LowCVSS 2.8

Open Redirect on FortiSIEM

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

Affected productsFortiSIEM
Fortinet PSIRT AdvisoriesFG-IR-26-173
LowCVSS 2.5

Null Pointer Dereference in Log Report

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Affected productsFortiOS, FortiProxy, FortiPAM
Fortinet PSIRT AdvisoriesFG-IR-26-167
MediumCVSS 6.7

Cron Job Injection in Remote Backup

CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00

Affected productsFortiSandbox
Fortinet PSIRT AdvisoriesFG-IR-26-164
MediumCVSS 4.9

Broken Access control on Websocket streams

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 202...

Affected productsFortiSOAR
Fortinet PSIRT AdvisoriesFG-IR-22-059
HighCVSS 7.5

Vulnerability in OpenSSL library

CVSSv3 Score: 7.5 A security advisory was released affecting the version of OpenSSL library used in some Fortinet products:CVE-2022-0778:The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Int...

Vendor guidance

It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022.Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1).

Fortinet PSIRT AdvisoriesFG-IR-26-163
MediumCVSS 5.8

HTTP/2 Bomb CVE-2026-49975

CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-19 00:00:00

Fortinet PSIRT AdvisoriesFG-IR-26-160
HighCVSS 7.3

FGFM Authentication Weakening via CLI Configuration

CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via ...

Affected productsFortiManager, FortiManager Cloud, FortiGate
Fortinet PSIRT AdvisoriesFG-IR-26-162
MediumCVSS 5.0

UI DoS attack

CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

Affected productsFortiOS
Fortinet PSIRT AdvisoriesFG-IR-26-161
MediumCVSS 5.1

Stack buffer overflow in WAD

CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if ...

Affected productsFortiOS
Fortinet PSIRT AdvisoriesFG-IR-26-159
LowCVSS 3.4

Server-Side Request Forgery (SSRF)

CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests Revised on 2026-08-12 00:00:00

Affected productsFortiSIEM
Fortinet PSIRT AdvisoriesFG-IR-26-157
MediumCVSS 4.8

Content-Encoding WAF Evasion

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

Affected productsFortiWeb
Fortinet PSIRT AdvisoriesFG-IR-26-146
HighCVSS 7.0

Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00

Affected productsFortiAuthenticator
Fortinet PSIRT AdvisoriesFG-IR-26-148
MediumCVSS 5.9

Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-0...

Affected productsFortiOS, FortiProxy, FortiPAM
Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.