Skip to content
COOEY

FAIL › dossier

Fortinet

VENDOR

· dossier confidence 60%

Fortinet is a public cybersecurity vendor with a significant market cap of $117.68B, but faces recurring critical vulnerabilities in core products including FortiOS and FortiClient EMS. Recent failures include unauthenticated RCE and authentication bypass flaws that pose severe risks to defense-industrial-base networks.

PROFILE
CategoryCybersecurity VendorWhat they doFortinet is a global leader in cybersecurity solutions and network security, providing hardware and software products for enterprise and government networks.SizeLargeOwnershippublic Websitehttps://www.fortinet.com ↗
SECURITY POSTURE

Fortinet demonstrates a pattern of high-severity vulnerabilities in critical infrastructure products (FortiOS, FortiClient EMS, FortiManager) with multiple unauthenticated RCE and authentication bypass flaws in 2024-2026.

Notable failures
  • CVE-2026-21643: Unauthenticated RCE via SQL injection in FortiClient EMS
  • CVE-2026-35616: Unauthenticated RCE via crafted requests in FortiClient EMS
  • CVE-2024-55591: Critical authentication bypass in FortiOS 7.0.x via alternate channel
  • CVE-2024-48884: Path traversal vulnerability in FortiManager 7.4.x-7.6.x
  • CVE-2024-48885: Path traversal vulnerability in FortiRecorder 7.0.x-7.2.x
  • CVE-2024-35276: Stack-based buffer overflow in FortiAnalyzer 7.0.x-7.4.x
Patterns: Repeated unauthenticated RCE in FortiClient EMS; Critical authentication bypass in FortiOS 7.0.x; Path traversal vulnerabilities across FortiManager/FortiRecorder; Stack-based buffer overflow in FortiAnalyzer
FAILURE HISTORY · 39
DATEEVENTSEVSUMMARY
2026-07-16 CVE-2026-39808 high Fortinet FortiSandbox OS Command Injection actively exploited without patch
2025-01-14 CVE-2024-55591 critical An unauthenticated remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via a Node.js websocket module flaw.
2026-04-13 CVE-2026-21643 high Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via SQL injection.
2026-04-06 CVE-2026-35616 high Fortinet FortiClient EMS allows unauthenticated attackers to execute arbitrary code via crafted requests.
2025-06-25 CVE-2019-6693 critical Fortinet FortiOS shipped with hard-coded credentials allowing attackers to decrypt sensitive data from configuration backups.
2025-03-18 CVE-2025-24472 critical A remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via crafted CSF proxy requests.
2024-10-23 CVE-2024-47575 high Fortinet FortiManager allows remote, unauthenticated attackers to execute arbitrary code via a missing authentication flaw in the fgfmd daemon.
2024-10-09 CVE-2024-23113 high Fortinet products allow remote, unauthenticated attackers to execute arbitrary code via a format string vulnerability.
2024-03-25 CVE-2023-48788 critical An unauthenticated SQL injection in Fortinet FortiClient EMS allowed attackers to execute SYSTEM commands, leading to ransomware-linked breaches.
2024-02-09 CVE-2024-21762 critical Fortinet FortiOS suffered a critical out-of-bounds write vulnerability allowing unauthenticated remote code execution.
2023-06-13 CVE-2023-27997 critical A heap-based buffer overflow in Fortinet FortiOS and FortiProxy SSL-VPN allows unauthenticated remote attackers to execute arbitrary code.
2022-12-13 CVE-2022-42475 critical Fortinet FortiOS SSL-VPN suffered a heap-based buffer overflow allowing unauthenticated remote code execution.
2022-10-11 CVE-2022-40684 critical An unauthenticated attacker could bypass authentication on Fortinet FortiOS, FortiProxy, and FortiSwitchManager via crafted HTTP/HTTPS requests, enabling administrative operations.
2026-07-27 CVE-2025-68686 high A bypass vulnerability in FortiOS allows attackers to access sensitive information after initial compromise, circumventing previous patches and requiring immediate action for DIB organizations using the product.
2026-07-16 CVE-2026-25089 high Fortinet FortiSandbox OS Command Injection Vulnerability actively exploited before July 19, 2026
2026-01-27 CVE-2026-24858 high Fortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO.
2025-12-16 CVE-2025-59718 high Fortinet products allow unauthenticated attackers to bypass authentication via crafted SAML messages
2025-11-18 CVE-2025-58034 high Fortinet FortiWeb OS command injection allowed unauthorized code execution by authenticated attackers.
2025-11-14 CVE-2025-64446 high FortiWeb RCE due to unpatched path traversal
2025-07-18 CVE-2025-25257 high FortiWeb SQL Injection allowed unauthenticated attackers to execute SQL code.
2025-05-14 CVE-2025-32756 high Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild.
2023-03-14 CVE-2022-41328 high FortiOS RCE flaw exploited in wild
2022-09-08 CVE-2018-13374 critical Fortinet FortiOS and FortiADC allowed attackers to steal LDAP credentials by redirecting connectivity test requests to a rogue server.
2022-01-10 CVE-2018-13383 critical Fortinet's FortiOS and FortiProxy had a critical heap buffer overflow exploited in the wild, potentially disrupting SSL VPN services for logged-in users.
2022-01-10 CVE-2018-13382 critical Unauthenticated attackers could modify passwords on Fortinet SSL VPN portals due to improper authorization vulnerabilities, actively exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2020-12812 critical Fortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA).
2021-11-03 CVE-2018-13379 critical Fortinet's FortiOS allowed unauthenticated attackers to download system files via a path traversal vulnerability, actively exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2019-5591 high Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.
2021-12-10 CVE-2021-44168 high Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to arbitrarily download files.
2025-01-14 CVE-2024-55591 critical An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to 
2024-03-12 CVE-2023-42789 critical A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, F
2025-01-14 CVE-2024-48884 high A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.4, FortiOS 7.2.0 through
2025-01-16 CVE-2024-48885 medium A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7
2025-01-14 CVE-2024-35276 medium A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 through 7.0.12, FortiAnalyzer 6.4.0 through 6.4.14, FortiAnalyzer Cloud 7.4.1 through 7.4.3, FortiAnalyzer Cloud 7.2.1 through 7.2.5,
2026-07-14 CVE-2026-59836 high CVE-2026-59836: A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3
2024-02-09 CVE-2024-21762 critical CVE-2024-21762: A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th
2023-06-13 CVE-2023-27997 critical CVE-2023-27997: A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an
2022-10-18 CVE-2022-40684 critical CVE-2022-40684: An authentication bypass using an alternate path or channel [CWE-288] in Fortine
2020-07-24 CVE-2020-12812 critical CVE-2020-12812: An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.60
Vulnerability bypasses MFA via case-change exploit, undermining core security controls.
app.opencve.io ↗severe-fallout-1.00
"…"
xposedornot.com ↗severe-fallout-1.00
"…"
cvefeed.io ↗severe-fallout-1.00
"…"
securityonline.info ↗severe-fallout-1.00
"…"
www.hipaajournal.com ↗severe-fallout-1.00
"…"
www.cvefind.com ↗severe-fallout-1.00
"…"
cooey ↗severe-fallout-1.00
"…"
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-1.00
"…"
cooey ↗severe-fallout-0.60
Vulnerability bypasses MFA via case-change exploit, undermining core security controls.
"An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username."
Open questions: Impact of CVE-2024-55591 on deployed FortiOS 7.0.0-7.0.16 systems · Remediation timeline for CVE-2026-21643 and CVE-2026-35616
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:51:56.822385+00:00