FAIL › dossier
Fortinet
VENDOR· dossier confidence 60%
Fortinet is a public cybersecurity vendor with a significant market cap of $117.68B, but faces recurring critical vulnerabilities in core products including FortiOS and FortiClient EMS. Recent failures include unauthenticated RCE and authentication bypass flaws that pose severe risks to defense-industrial-base networks.
PROFILE
CategoryCybersecurity VendorWhat they doFortinet is a global leader in cybersecurity solutions and network security, providing hardware and software products for enterprise and government networks.SizeLargeOwnershippublic
Websitehttps://www.fortinet.com ↗
SECURITY POSTURE
Fortinet demonstrates a pattern of high-severity vulnerabilities in critical infrastructure products (FortiOS, FortiClient EMS, FortiManager) with multiple unauthenticated RCE and authentication bypass flaws in 2024-2026.
Notable failures
- CVE-2026-21643: Unauthenticated RCE via SQL injection in FortiClient EMS
- CVE-2026-35616: Unauthenticated RCE via crafted requests in FortiClient EMS
- CVE-2024-55591: Critical authentication bypass in FortiOS 7.0.x via alternate channel
- CVE-2024-48884: Path traversal vulnerability in FortiManager 7.4.x-7.6.x
- CVE-2024-48885: Path traversal vulnerability in FortiRecorder 7.0.x-7.2.x
- CVE-2024-35276: Stack-based buffer overflow in FortiAnalyzer 7.0.x-7.4.x
Patterns: Repeated unauthenticated RCE in FortiClient EMS; Critical authentication bypass in FortiOS 7.0.x; Path traversal vulnerabilities across FortiManager/FortiRecorder; Stack-based buffer overflow in FortiAnalyzer
FAILURE HISTORY · 39
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-07-16 | CVE-2026-39808 | high | Fortinet FortiSandbox OS Command Injection actively exploited without patch |
| 2025-01-14 | CVE-2024-55591 | critical | An unauthenticated remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via a Node.js websocket module flaw. |
| 2026-04-13 | CVE-2026-21643 | high | Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via SQL injection. |
| 2026-04-06 | CVE-2026-35616 | high | Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via crafted requests. |
| 2025-06-25 | CVE-2019-6693 | critical | Fortinet FortiOS shipped with hard-coded credentials allowing attackers to decrypt sensitive data from configuration backups. |
| 2025-03-18 | CVE-2025-24472 | critical | A remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via crafted CSF proxy requests. |
| 2024-10-23 | CVE-2024-47575 | high | Fortinet FortiManager allows remote, unauthenticated attackers to execute arbitrary code via a missing authentication flaw in the fgfmd daemon. |
| 2024-10-09 | CVE-2024-23113 | high | Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability. |
| 2024-03-25 | CVE-2023-48788 | critical | An unauthenticated SQL injection in Fortinet FortiClient EMS allowed attackers to execute SYSTEM commands, leading to ransomware-linked breaches. |
| 2024-02-09 | CVE-2024-21762 | critical | Fortinet FortiOS suffered a critical out-of-bounds write vulnerability allowing unauthenticated remote code execution. |
| 2023-06-13 | CVE-2023-27997 | critical | A heap-based buffer overflow in Fortinet FortiOS and FortiProxy SSL-VPN allows unauthenticated remote attackers to execute arbitrary code. |
| 2022-12-13 | CVE-2022-42475 | critical | Fortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution. |
| 2022-10-11 | CVE-2022-40684 | critical | An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations. |
| 2026-07-27 | CVE-2025-68686 | high | A bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product. |
| 2026-07-16 | CVE-2026-25089 | high | Fortinet FortiSandbox OS Command Injection Vulnerability actively exploited before July 19, 2026 |
| 2026-01-27 | CVE-2026-24858 | high | Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO. |
| 2025-12-16 | CVE-2025-59718 | high | Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages |
| 2025-11-18 | CVE-2025-58034 | high | Fortinet FortiWeb OS command injection allowed unauthorized code execution by authenticated attackers. |
| 2025-11-14 | CVE-2025-64446 | high | FortiWeb RCE due to unpatched path traversal |
| 2025-07-18 | CVE-2025-25257 | high | FortiWeb SQL Injection allowed unauthenticated attackers to execute SQL code. |
| 2025-05-14 | CVE-2025-32756 | high | Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild. |
| 2023-03-14 | CVE-2022-41328 | high | FortiOS RCE flaw exploited in wild |
| 2022-09-08 | CVE-2018-13374 | critical | Fortinet FortiOS and FortiADC allowed attackers to steal LDAP credentials by redirecting connectivity test requests to a rogue server. |
| 2022-01-10 | CVE-2018-13383 | critical | Fortinet's FortiOS and FortiProxy had a critical heap buffer overflow exploited in the wild, potentially disrupting SSL VPN services for logged-in users. |
| 2022-01-10 | CVE-2018-13382 | critical | Unauthenticated attackers could modify passwords on Fortinet SSL VPN portals due to improper authorization vulnerabilities, actively exploited in the wild and linked to ransomware activity. |
| 2021-11-03 | CVE-2020-12812 | critical | Fortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA). |
| 2021-11-03 | CVE-2018-13379 | critical | Fortinet's FortiOS allowed unauthenticated attackers to download system files via a path traversal vulnerability, actively exploited in the wild and linked to ransomware activity. |
| 2021-11-03 | CVE-2019-5591 | high | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. |
| 2021-12-10 | CVE-2021-44168 | high | Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files. |
| 2025-01-14 | CVE-2024-55591 | critical | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to |
| 2024-03-12 | CVE-2023-42789 | critical | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, F |
| 2025-01-14 | CVE-2024-48884 | high | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through |
| 2025-01-16 | CVE-2024-48885 | medium | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7 |
| 2025-01-14 | CVE-2024-35276 | medium | A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7.2.1 through 7.2.5, |
| 2026-07-14 | CVE-2026-59836 | high | CVE-2026-59836: A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 |
| 2024-02-09 | CVE-2024-21762 | critical | CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th |
| 2023-06-13 | CVE-2023-27997 | critical | CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an |
| 2022-10-18 | CVE-2022-40684 | critical | CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine |
| 2020-07-24 | CVE-2020-12812 | critical | CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6 |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.60
Vulnerability bypasses MFA via case-change exploit, undermining core security controls.
Vulnerability bypasses MFA via case-change exploit, undermining core security controls.
"An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username."
DOSSIER SOURCES
- Fortinet (FTNT) Company Profile, History, Products & Services · www.financecharts.com
- Fortinet, Inc. - Company Profile - WealthRank · www.wealthrank.in
- Fortinet stock in July (2026) | Analysis, price target & growth · growthinvesting.net
- Fortinet CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Fortios CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- FortiOS: Releases, patches & end-of-life · www.versio.io
Open questions: Impact of CVE-2024-55591 on deployed FortiOS 7.0.0-7.0.16 systems · Remediation timeline for CVE-2026-21643 and CVE-2026-35616
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:51:56.822385+00:00