CVE-2026-22153
- EPSS 0.7%
- Veröffentlicht 10.02.2026 15:39:12
- Zuletzt bearbeitet 12.02.2026 16:03:10
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP serve...
CVE-2026-25815
- EPSS 0.11%
- Veröffentlicht 05.02.2026 21:14:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). ...
CVE-2026-24858
- EPSS 85.84%
- Veröffentlicht 27.01.2026 19:18:23
- Zuletzt bearbeitet 09.06.2026 18:30:13
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15...
CVE-2025-25249
- EPSS 0.76%
- Veröffentlicht 13.01.2026 16:32:35
- Zuletzt bearbeitet 07.10.2026 18:17:13
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitch...
CVE-2024-40593
- EPSS 0.11%
- Veröffentlicht 11.12.2025 14:10:08
- Zuletzt bearbeitet 02.10.2026 00:10:00
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5...
CVE-2024-47570
- EPSS 0.4%
- Veröffentlicht 09.12.2025 17:20:42
- Zuletzt bearbeitet 02.10.2026 00:10:00
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 ...
CVE-2025-59718
- EPSS 63.44%
- Veröffentlicht 09.12.2025 17:20:11
- Zuletzt bearbeitet 09.06.2026 12:47:10
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 throug...
CVE-2025-62631
- EPSS 0.3%
- Veröffentlicht 09.12.2025 17:18:47
- Zuletzt bearbeitet 14.01.2026 10:16:08
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSL...
CVE-2025-53843
- EPSS 0.59%
- Veröffentlicht 18.11.2025 17:01:28
- Zuletzt bearbeitet 09.06.2026 10:16:38
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to execute unauthorized code or commands vi...
- EPSS 0.15%
- Veröffentlicht 18.11.2025 17:01:22
- Zuletzt bearbeitet 23.06.2026 13:16:38
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 a...