Fortinet
- 7
- vulnerabilities tracked
- 3
- under active exploitation
- 1
- critical
- 27 July 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnerabilityFortinet FortiOS Critical CVE-2026-25089Fortinet FortiSandbox OS Command Injection VulnerabilityFortinet FortiSandbox Critical CVE-2026-39808Fortinet FortiSandbox OS Command Injection VulnerabilityFortinet FortiSandbox Critical CVE-2025-53379A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.Fortinet Fortiauthenticator High CVSS 7.5 CVE-2026-59835A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.Fortinet Fortisandbox High CVSS 8.6 CVE-2026-59836A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>Fortinet Forticlientems Critical CVSS 9.8 CVE-2026-59841A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>Fortinet Fortisiem High CVSS 7.5