Vendor advisories

Fortinet PSIRT Advisories

Browse 40 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 17 minutes ago Checked every 15 minutes

40 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Fortinet PSIRT AdvisoriesFG-IR-26-150
MediumCVSS 6.1

SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via cr...

Affected productsFortiOS, FortiProxy, FortiPAM, FortiSwitch-Manager
Fortinet PSIRT AdvisoriesFG-IR-26-151
MediumCVSS 5.0

Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the fi...

Affected productsFortiOS, FortiPAM, FortiProxy, FortiSwitch
Fortinet PSIRT AdvisoriesFG-IR-26-152
LowCVSS 3.4

Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user...

Affected productsFortiOS, FortiProxy
Fortinet PSIRT AdvisoriesFG-IR-26-149
MediumCVSS 5.3

Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

Affected productsFortiSIEM
Fortinet PSIRT AdvisoriesFG-IR-26-154
MediumCVSS 4.1

Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

Affected productsFortiOS, FortiProxy, FortiSASE
Fortinet PSIRT AdvisoriesFG-IR-26-141
CriticalCVSS 9.1

Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP r...

Affected productsFortiSandbox, FortiSandbox Cloud
Fortinet PSIRT AdvisoriesFG-IR-26-143
MediumCVSS 6.0

Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00

Affected productsFortiOS, FortiProxy
Fortinet PSIRT AdvisoriesFG-IR-26-140
MediumCVSS 6.2

Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00

Affected productsFortiPortal
Fortinet PSIRT AdvisoriesFG-IR-25-545
LowCVSS 1.8

Trusted hosts bypass via SSH

CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00

Affected productsFortiOS, FortiProxy, FortiPAM
Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.