CyberMax
Home › Exploited CVEs

Fortinet known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 30 Fortinet CVEs as exploited in the wild. 10 were added in the last 12 months (latest 2026-09-09), and 14 are known to be used in ransomware campaigns.

Fortinet CVEs added to CISA KEV per year
2021: 4202142022: 5202252023: 2202322024: 4202442025: 8202582026: 720267

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Fortinet products

FortiOS (9), Multiple Products (6), FortiOS and FortiProxy (4), FortiClient EMS (3), FortiWeb (3), FortiSandbox (2), FortiManager (1), FortiOS and FortiProxy SSL-VPN (1), FortiOS and FortiADC (1).

All Fortinet CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-25249Multiple ProductsMultiple Products Heap-based Buffer Overflow2026-09-092026-09-123.9%–
CVE-2025-68686FortiOSFortiOS Exposure of Sensitive Information to an Unauthorized Actor2026-07-272026-08-1029.6%–
CVE-2026-39808FortiSandboxFortiSandbox OS Command Injection2026-07-162026-07-1947.4%–
CVE-2026-25089FortiSandboxFortiSandbox OS Command Injection2026-07-162026-07-1976.1%–
CVE-2026-21643FortiClient EMSFortiClient EMS SQL Injection2026-04-132026-04-1693.7%–
CVE-2026-35616FortiClient EMSFortiClient EMS Improper Access Control2026-04-062026-04-099.1%–
CVE-2026-24858Multiple ProductsMultiple Products Authentication Bypass Using an Alternate Path or Channel2026-01-272026-01-3085.8%–
CVE-2025-59718Multiple ProductsMultiple Products Improper Verification of Cryptographic Signature2025-12-162025-12-2368.3%–
CVE-2025-58034FortiWebFortiWeb OS Command Injection2025-11-182025-11-2555.6%–
CVE-2025-64446FortiWebFortiWeb Path Traversal2025-11-142025-11-2191.8%–
CVE-2025-25257FortiWebFortiWeb SQL Injection2025-07-182025-08-0899.8%–
CVE-2019-6693FortiOSFortiOS Use of Hard-Coded Credentials2025-06-252025-07-165.8%Yes
CVE-2025-32756Multiple ProductsMultiple Products Stack-Based Buffer Overflow2025-05-142025-06-0429.8%–
CVE-2025-24472FortiOS and FortiProxyFortiOS and FortiProxy Authentication Bypass2025-03-182025-04-087.2%Yes
CVE-2024-55591FortiOS and FortiProxyFortiOS and FortiProxy Authentication Bypass2025-01-142025-01-2194.1%Yes
CVE-2024-47575FortiManagerFortiManager Missing Authentication2024-10-232024-11-1394.8%–
CVE-2024-23113Multiple ProductsMultiple Products Format String2024-10-092024-10-3061.7%–
CVE-2023-48788FortiClient EMSFortiClient EMS SQL Injection2024-03-252024-04-1598.4%Yes
CVE-2024-21762FortiOSFortiOS Out-of-Bound Write2024-02-092024-02-1683.4%Yes
CVE-2023-27997FortiOS and FortiProxy SSL-VPNFortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow2023-06-132023-07-0485.7%Yes
CVE-2022-41328FortiOSFortiOS Path Traversal2023-03-142023-04-0410.7%–
CVE-2022-42475FortiOSFortiOS Heap-Based Buffer Overflow2022-12-132023-01-0399.5%Yes
CVE-2022-40684Multiple ProductsMultiple Products Authentication Bypass2022-10-112022-11-01100.0%Yes
CVE-2018-13374FortiOS and FortiADCFortiOS and FortiADC Improper Access Control2022-09-082022-09-2937.8%Yes
CVE-2018-13383FortiOS and FortiProxyFortiOS and FortiProxy Out-of-bounds Write2022-01-102022-07-1033.6%Yes
CVE-2018-13382FortiOS and FortiProxyFortiOS and FortiProxy Improper Authorization2022-01-102022-07-1081.7%Yes
CVE-2021-44168FortiOSFortiOS Arbitrary File Download2021-12-102021-12-240.9%–
CVE-2020-12812FortiOSFortiOS SSL VPN Improper Authentication2021-11-032022-05-0349.3%Yes
CVE-2019-5591FortiOSFortiOS Default Configuration2021-11-032022-05-0318.4%Yes
CVE-2018-13379FortiOSFortiOS SSL VPN Path Traversal2021-11-032022-05-03100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors