Skip to content
VulniPulse

Fortinet FortiProxy Vulnerabilities & Security Advisories

28 advisories tracked · FortiGuard PSIRT Advisories · 7 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Fortinet advisory that VulniPulse classified as FortiProxy, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 2 high, 14 medium, 5 low.

Android app · Google Play

Monitor Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

FortiGuard PSIRT Advisories

Polled via the official FortiGuard PSIRT RSS feed (filestore.fortinet.com). PSIRT pages are fetched for new items to extract affected and fixed versions.

Latest Fortinet FortiProxy advisories

Low2.6Fortinet

Low [CVE-2025-31514] Insertion of Sensitive 2FA Information in logs and debug command

CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00 Affected products named by the advisory: FortiProxy.

CVE-2025-31514
FortiGateFirewallFortiOSFortiProxy
Oct 14, 2025
Medium6.3Fortinet

Medium [CVE-2025-22862] Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.

CVE-2025-22862
FortiGateFirewallFortiOSFortiProxy
Oct 2, 2025
Medium4.8Fortinet

Medium [CVE-2025-25248] Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version…

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.

CVE-2025-25248
FortiGateFirewallFortiOSFortiProxy
Aug 12, 2025
Medium4.9Fortinet

Medium [CVE-2024-55599] Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below…

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices. Affected products named by the advisory: FortiSASE.

CVE-2024-55599
FortiGateFirewallFortiOSFortiProxy
Jul 8, 2025
Critical9.6Vendor: HighFortinet Exploited CISA KEV

Critical [CVE-2024-55591 +1] Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

CVE-2024-55591CVE-2025-24472
FortiGateFirewallFortiOSFortiProxy
Feb 11, 2025
Critical9.6Fortinet Exploited CISA KEV

Critical [CVE-2024-55591 +1] Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVE-2024-55591CVE-2025-24472
FortiGateFirewallFortiOSFortiProxy
Jan 14, 2025
Critical9.2Fortinet Exploited CISA KEV

Critical [CVE-2023-27997] FortiOS-6K7K: heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests. Affected products named by the advisory: FortiOS-6K7K.

CVE-2023-27997
FortiGateFirewallFortiOSFortiProxy
Jun 13, 2023
Critical9.6Fortinet Exploited CISA KEV

Critical [CVE-2022-40684] Fortinet FortiOS, FortiProxy, FortiSwitchManager: authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Affected product named by the advisory: Fortinet FortiOS, FortiProxy, FortiSwitchManager.

CVE-2022-40684
FortiGateFirewallFortiOSFortiProxy
Oct 18, 2022

← All Fortinet advisories