Fortinet Multiple Products known exploited vulnerabilities, ranked
CISA lists 6 Fortinet Multiple Products CVEs as exploited in the wild. 3 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2022-40684: EPSS 99.98%, used in ransomware, added 2022-10-11
- CVE-2026-24858: EPSS 85.8%, added 2026-01-27
- CVE-2025-59718: EPSS 68.3%, added 2025-12-16
- CVE-2024-23113: EPSS 61.7%, added 2024-10-09
- CVE-2025-32756: EPSS 29.8%, added 2025-05-14
All 6 Fortinet Multiple Products CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2022-40684 | Multiple Products Authentication Bypass | 99.98% | Yes | 2022-10-11 | 2022-11-01 |
| 2 | CVE-2026-24858 | Multiple Products Authentication Bypass Using an Alternate Path or Channel | 85.8% | – | 2026-01-27 | 2026-01-30 |
| 3 | CVE-2025-59718 | Multiple Products Improper Verification of Cryptographic Signature | 68.3% | – | 2025-12-16 | 2025-12-23 |
| 4 | CVE-2024-23113 | Multiple Products Format String | 61.7% | – | 2024-10-09 | 2024-10-30 |
| 5 | CVE-2025-32756 | Multiple Products Stack-Based Buffer Overflow | 29.8% | – | 2025-05-14 | 2025-06-04 |
| 6 | CVE-2025-25249 | Multiple Products Heap-based Buffer Overflow | 3.9% | – | 2026-09-09 | 2026-09-12 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Fortinet KEV CVEs · other Fortinet products: FortiOS · free KEV badge for Fortinet · all vendors