Home/News

Security & Lifecycle News

Aggregated from vendor advisories, security research, and industry publications.

FortiGuard PSIRT Advisories

MFA Bypass in GUI

CVSSv3 Score: 6.8 An authentication bypass using an alternate path or channel vulnerability [CWE-288] in FortiManager and FortiAnalyzer multifactor authentication may allow a…

FortiGuard PSIRT Advisories

OS Command injection in FortiWeb API

CVSSv3 Score: 6.7 An OS Command Injection vulnerability [CWE-78] in FortiWeb API may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP…

FortiGuard PSIRT Advisories

Privilege escalation using undocumented CLI command

CVSSv3 Score: 6.4 An Inclusion of Undocumented Features [CWE-1242] in FortiManager and FortiAnalyzer CLI may allow a remote authenticated read-only admin with CLI access to e…

FortiGuard PSIRT Advisories

Protected hostname bypass

CVSSv3 Score: 5.0 An authentication bypass by spoofing [CWE-290] vulnerability in FortiWeb protected hostname feature may allow a remote unauthenticated attacker to bypass ho…

FortiGuard PSIRT Advisories

SQL injection in jsonrpc api

CVSSv3 Score: 5.6 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiAnalyzer and FortiAnalyzer-BigData AP…

FortiGuard PSIRT Advisories

Stack buffer overflow in API

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiWeb may allow a remote authenticated attacker who can bypass stack protection and ASLR to exec…

FortiGuard PSIRT Advisories

Stack-based Buffer Overflow in API protection

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiWeb may allow a remote authenticated attacker to execute arbitrary code or commands via crafte…

FortiGuard PSIRT Advisories

SSL-VPN Symlink Persistence Patch Bypass

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypa…

FortiGuard PSIRT Advisories

OpenSSL CVE-2025-15467

CVSSv3 Score: 9.8 CVE-2025-15467Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. A stack buffer overflow ma…

CVE-2025-15467
↑ Top