Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.0Fortinet

Medium [CVE-2026-25690] Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00

CVE-2026-25690
Unclassified
May 12, 2026
Medium6.1Fortinet

Medium [CVE-2025-53680] Command injection in CLI

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00

CVE-2025-53680
FortiAP
May 12, 2026
Medium5.2Fortinet

Medium [CVE-2025-67604] DoS due to unsafe function in signal handler

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00

CVE-2025-67604
FortiManagerFortiAnalyzer
May 12, 2026
Medium6.5Fortinet

Medium [CVE-2025-53870] OS command injection in CLI

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00

CVE-2025-53870
FortiAP
May 12, 2026
Medium5.0Fortinet

Medium [CVE-2026-44279] OTP Disclosure via Exported TokenContentProvider

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

CVE-2026-44279
Unclassified
May 12, 2026
Medium6.3Fortinet

Medium [CVE-2025-53681] SQL command injection in administrative portal

CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests. Revised on 2026-05-12 00:00:00

CVE-2025-53681
FortiMail
May 12, 2026
Medium5.1Fortinet

Medium [CVE-2026-25088] User controlled SQL commands

CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests. Revised on 2026-05-12 00:00:00

CVE-2026-25088
Unclassified
May 12, 2026
Low2.1Fortinet

Low [CVE-2026-44278] Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

CVE-2026-44278
FortiClient
May 12, 2026
Medium6.7Fortinet

Medium [CVE-2026-40688] Out-Of-Bounds Write in administrative interface

CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. Revised on 2026-04-15 00:00:00

CVE-2026-40688
FortiWeb
Apr 15, 2026
Critical9.1Fortinet Exploited CISA KEV

Critical [CVE-2026-39808] OS Command Injection through API endpoint

CVSSv3 Score: 9.1 An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-04-14 00:00:00 Affected product named by the advisory: FortiSandbox PaaS.

CVE-2026-39808
FortiSandbox
Apr 14, 2026
Critical9.1Fortinet

Critical [CVE-2026-39813] Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox

CVSSv3 Score: 9.1 A Path Traversal vulnerability [CWE-24] in FortiSandbox JRPC API may allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests. Revised on 2026-04-14 00:00:00

CVE-2026-39813
FortiSandbox
Apr 14, 2026
High7.3Fortinet

High [CVE-2026-22828] Heap-based buffer overflow in oftpd daemon

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation Revised on 2026-04-14 00:00:00

CVE-2026-22828
FortiAnalyzer
Apr 14, 2026
High7.1Fortinet

High [CVE-2026-39809] Multiple SQL Injections

CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests. Revised on 2026-04-14 00:00:00

CVE-2026-39809
FortiClient
Apr 14, 2026
High7.9Fortinet

High [CVE-2026-39815] SQL Injection via API

CVSSv3 Score: 7.9 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiDDoS-F may allow an authenticated attacker to run arbitrary SQL queries on the database by sending crafted HTTP requests. Revised on 2026-04-14 00:00:00

CVE-2026-39815
Unclassified
Apr 14, 2026
Medium6.7Fortinet

Medium [CVE-2026-23708] 2FA request can be replayed without a valid token after one successful request

CVSSv3 Score: 6.7 An Improper authentication vulnerability [CWE-287] in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration. Revised on 2026-04-14 00:00:00

CVE-2026-23708
Unclassified
Apr 14, 2026
Medium6.2Fortinet

Medium [CVE-2026-25691] Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

CVE-2026-25691
FortiSandbox
Apr 14, 2026
Medium4.1Fortinet

Medium [CVE-2026-22574] Clear-text credentials retrievable with IP modification for LDAP

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257] in FortiSOAR may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration. Revised on 2026-04-14 00:00:00

CVE-2026-22574
Unclassified
Apr 14, 2026
Medium4.1Fortinet

Medium [CVE-2026-22576] Clear-text credentials retrievable with IP modification for connectors

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257] in FortiSOAR may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration. Revised on 2026-04-14 00:00:00

CVE-2026-22576
Unclassified
Apr 14, 2026
Medium6.2Fortinet

Medium [CVE-2026-21742 +1] Cleartext Credentials in response for API endpoints

CVSSv3 Score: 6.2 A Cleartext Transmission of Sensitive Information vulnerability [CWE-319] in FortiSOAR may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured Revised on 2026-04-14 00:00:00

CVE-2026-21742CVE-2026-22155
Unclassified
Apr 14, 2026
Medium5.2Fortinet

Medium [CVE-2026-39810] Hardcoded symmetric encryption key for Postgresql

CVSSv3 Score: 5.2 A use of hard-coded cryptographic key vulnerability [CWE 321] in FortiClientEMS may allow an attacker in possession of an encrypted dump of the database to decrypt it. Revised on 2026-04-14 00:00:00

CVE-2026-39810
FortiClient
Apr 14, 2026