Fortinet Security Advisories & CVEs
164 advisories tracked · FortiGuard PSIRT Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Check if your Fortinet device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Fortinet's recent advisories.
Official source
FortiGuard PSIRT Advisories
Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.
Latest Fortinet advisories
Critical [CVE-2026-104286] Improper limitation of a pathname to a restricted directory
CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-07 00:00:00 Affected product named by the advisory: FortiMail.
Critical [CVE-2026-84388] Improper Authentication of FortiPAM Server
CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Revised on 2026-09-08 00:00:00 Affected product named by the advisory: FortiPAM Chrome Extension.
Critical [CVE-2026-84390] JWT used for authentication in web GUI signed with static key
CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00
High [CVE-2026-84393] improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure
High [CVE-2026-26084] improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
High [CVE-2026-26084] Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00
High [CVE-2026-84393] ZTNA Portal Improper Certificate Validation
CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website. Revised on 2026-09-08 00:00:00
Medium [CVE-2026-22575] improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests
An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests.
Medium [CVE-2026-84391] use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>
A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service
Medium [CVE-2026-84385] improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege
Medium [CVE-2026-84387] improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands
Medium [CVE-2026-84386] unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector here>
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control
Medium [CVE-2026-84386] Arbitrary process termination from exposed minifilter communication port
CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00 Affected product named by the advisory: FortiClientWindows.
Medium [CVE-2026-84385] Broken Access control on Websocket streams
CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via crafted websocket requests Revised on 2026-09-08 00:00:00 Affected products named by the advisory: FortiSOAR PaaS; FortiSOAR on-premise.
Medium [CVE-2026-84387] Cron Job Injection in Remote Backup
CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00
Medium [CVE-2026-84391] Uncontrolled Resource Consumption in SNMP
CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00
Medium [CVE-2026-22575] Workflow session email approval process bypass
CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs requests. Revised on 2026-09-08 00:00:00 Affected product named by the advisory: FortiManager Cloud.
Low [CVE-2026-84392] NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.6, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.
Low [CVE-2026-84389] url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands
Low [CVE-2026-84392] Null Pointer Dereference in Log Report
CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00