CyberMax
Home › Exploited CVEs › Fortinet

Fortinet Multiple Products known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 6 Fortinet Multiple Products CVEs as exploited in the wild. 3 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 6 Fortinet Multiple Products CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2022-40684Multiple Products Authentication Bypass99.98%Yes2022-10-112022-11-01
2CVE-2026-24858Multiple Products Authentication Bypass Using an Alternate Path or Channel85.8%–2026-01-272026-01-30
3CVE-2025-59718Multiple Products Improper Verification of Cryptographic Signature68.3%–2025-12-162025-12-23
4CVE-2024-23113Multiple Products Format String61.7%–2024-10-092024-10-30
5CVE-2025-32756Multiple Products Stack-Based Buffer Overflow29.8%–2025-05-142025-06-04
6CVE-2025-25249Multiple Products Heap-based Buffer Overflow3.9%–2026-09-092026-09-12
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Fortinet KEV CVEs · other Fortinet products: FortiOS · free KEV badge for Fortinet · all vendors