VENDOR

Fortinet vulnerabilities: CVEs, exploitation and patches

Every Fortinet CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-84390
    FortiMonitorOnSight source-code sensitive information disclosure Fortinet FortiMonitorOnSight ·
    CRITICAL 9.8
  2. CVE-2026-26084 CRITICAL 9.9
  3. CVE-2026-26035 CRITICAL 9.8
  4. CVE-2026-84388
    FortiPAM Chrome Extension information disclosure via UI layer restriction Fortinet FortiPAM Chrome Extension ·
    • PoC PUBLIC
    CRITICAL 9.6
  5. CVE-2025-68686
    FortiOS exposure of sensitive information to unauthenticated remote actors Fortinet FortiOS ·
    • CISA KEV
    • EXPLOITED
    MEDIUM 5.9
  6. CVE-2025-25249
    Fortinet FortiOS and FortiSwitchManager heap buffer overflow remote code execution Fortinet Multiple Products ·
    • CISA KEV
    • EXPLOITED
    CRITICAL 9.8
  7. CVE-2026-39808
    FortiSandbox OS command injection unauthenticated remote code execution Fortinet FortiSandbox ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
  8. CVE-2026-25089
    FortiSandbox OS command injection unauthenticated remote command execution Fortinet FortiSandbox ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    CRITICAL 9.8
8 CVEs · page 1 of 1