Fortinet known exploited vulnerabilities
CISA lists 30 Fortinet CVEs as exploited in the wild. 10 were added in the last 12 months (latest 2026-09-09), and 14 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2018-13379 (FortiOS): EPSS 100.0%, added 2021-11-03
- CVE-2022-40684 (Multiple Products): EPSS 100.0%, added 2022-10-11
- CVE-2025-25257 (FortiWeb): EPSS 99.8%, added 2025-07-18
- CVE-2022-42475 (FortiOS): EPSS 99.5%, added 2022-12-13
- CVE-2023-48788 (FortiClient EMS): EPSS 98.4%, added 2024-03-25
Most affected Fortinet products
FortiOS (9), Multiple Products (6), FortiOS and FortiProxy (4), FortiClient EMS (3), FortiWeb (3), FortiSandbox (2), FortiManager (1), FortiOS and FortiProxy SSL-VPN (1), FortiOS and FortiADC (1).
All Fortinet CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-25249 | Multiple Products | Multiple Products Heap-based Buffer Overflow | 2026-09-09 | 2026-09-12 | 3.9% | – |
| CVE-2025-68686 | FortiOS | FortiOS Exposure of Sensitive Information to an Unauthorized Actor | 2026-07-27 | 2026-08-10 | 29.6% | – |
| CVE-2026-39808 | FortiSandbox | FortiSandbox OS Command Injection | 2026-07-16 | 2026-07-19 | 47.4% | – |
| CVE-2026-25089 | FortiSandbox | FortiSandbox OS Command Injection | 2026-07-16 | 2026-07-19 | 76.1% | – |
| CVE-2026-21643 | FortiClient EMS | FortiClient EMS SQL Injection | 2026-04-13 | 2026-04-16 | 93.7% | – |
| CVE-2026-35616 | FortiClient EMS | FortiClient EMS Improper Access Control | 2026-04-06 | 2026-04-09 | 9.1% | – |
| CVE-2026-24858 | Multiple Products | Multiple Products Authentication Bypass Using an Alternate Path or Channel | 2026-01-27 | 2026-01-30 | 85.8% | – |
| CVE-2025-59718 | Multiple Products | Multiple Products Improper Verification of Cryptographic Signature | 2025-12-16 | 2025-12-23 | 68.3% | – |
| CVE-2025-58034 | FortiWeb | FortiWeb OS Command Injection | 2025-11-18 | 2025-11-25 | 55.6% | – |
| CVE-2025-64446 | FortiWeb | FortiWeb Path Traversal | 2025-11-14 | 2025-11-21 | 91.8% | – |
| CVE-2025-25257 | FortiWeb | FortiWeb SQL Injection | 2025-07-18 | 2025-08-08 | 99.8% | – |
| CVE-2019-6693 | FortiOS | FortiOS Use of Hard-Coded Credentials | 2025-06-25 | 2025-07-16 | 5.8% | Yes |
| CVE-2025-32756 | Multiple Products | Multiple Products Stack-Based Buffer Overflow | 2025-05-14 | 2025-06-04 | 29.8% | – |
| CVE-2025-24472 | FortiOS and FortiProxy | FortiOS and FortiProxy Authentication Bypass | 2025-03-18 | 2025-04-08 | 7.2% | Yes |
| CVE-2024-55591 | FortiOS and FortiProxy | FortiOS and FortiProxy Authentication Bypass | 2025-01-14 | 2025-01-21 | 94.1% | Yes |
| CVE-2024-47575 | FortiManager | FortiManager Missing Authentication | 2024-10-23 | 2024-11-13 | 94.8% | – |
| CVE-2024-23113 | Multiple Products | Multiple Products Format String | 2024-10-09 | 2024-10-30 | 61.7% | – |
| CVE-2023-48788 | FortiClient EMS | FortiClient EMS SQL Injection | 2024-03-25 | 2024-04-15 | 98.4% | Yes |
| CVE-2024-21762 | FortiOS | FortiOS Out-of-Bound Write | 2024-02-09 | 2024-02-16 | 83.4% | Yes |
| CVE-2023-27997 | FortiOS and FortiProxy SSL-VPN | FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow | 2023-06-13 | 2023-07-04 | 85.7% | Yes |
| CVE-2022-41328 | FortiOS | FortiOS Path Traversal | 2023-03-14 | 2023-04-04 | 10.7% | – |
| CVE-2022-42475 | FortiOS | FortiOS Heap-Based Buffer Overflow | 2022-12-13 | 2023-01-03 | 99.5% | Yes |
| CVE-2022-40684 | Multiple Products | Multiple Products Authentication Bypass | 2022-10-11 | 2022-11-01 | 100.0% | Yes |
| CVE-2018-13374 | FortiOS and FortiADC | FortiOS and FortiADC Improper Access Control | 2022-09-08 | 2022-09-29 | 37.8% | Yes |
| CVE-2018-13383 | FortiOS and FortiProxy | FortiOS and FortiProxy Out-of-bounds Write | 2022-01-10 | 2022-07-10 | 33.6% | Yes |
| CVE-2018-13382 | FortiOS and FortiProxy | FortiOS and FortiProxy Improper Authorization | 2022-01-10 | 2022-07-10 | 81.7% | Yes |
| CVE-2021-44168 | FortiOS | FortiOS Arbitrary File Download | 2021-12-10 | 2021-12-24 | 0.9% | – |
| CVE-2020-12812 | FortiOS | FortiOS SSL VPN Improper Authentication | 2021-11-03 | 2022-05-03 | 49.3% | Yes |
| CVE-2019-5591 | FortiOS | FortiOS Default Configuration | 2021-11-03 | 2022-05-03 | 18.4% | Yes |
| CVE-2018-13379 | FortiOS | FortiOS SSL VPN Path Traversal | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors