# ANSSI Flags Multiple Fortinet Product Vulnerabilities

Published: 2026-09-11 · Severity: routine · Sectors: technology, government-national, telecommunications, financial-services
Canonical: https://vorant.io/reports/049d90d5-3f7c-5de8-b202-eae726251c0e/anssi-flags-multiple-fortinet-product-vulnerabilities

> ANSSI advisory details 11 CVEs across Fortinet's product line enabling RCE, privilege escalation, and DoS; patches available.

CERT-FR published an advisory summarizing multiple vulnerabilities affecting a broad range of Fortinet products, including FortiOS, FortiAnalyzer, FortiManager, FortiClient, FortiPAM, FortiSandbox, FortiSIEM, and FortiSOAR. The flaws collectively allow attackers to achieve remote code execution, privilege escalation, remote denial of service, data integrity and confidentiality breaches, and security policy bypass, depending on the specific product and CVE. No indication of active exploitation in the wild is mentioned in this advisory.

The affected versions span numerous Fortinet product lines and their respective cloud/PaaS variants, indicating a coordinated patch cycle covering 11 separate Fortinet PSIRT bulletins (FG-IR-26-164 through FG-IR-26-174) released on 8 September 2026. Eleven CVEs were referenced (CVE-2026-22575, CVE-2026-26084, and CVE-2026-84385 through CVE-2026-84393), though the advisory does not break down which CVE maps to which specific product or vulnerability type.

Defenders operating any of the listed Fortinet products should prioritize patching to the fixed versions identified (e.g., FortiOS 7.6.7, FortiManager 7.6.5/7.4.11, FortiSIEM 7.5.2, FortiPAM 1.9.1, FortiSandbox 5.2.1/5.0.7/4.4.10, FortiSOAR 7.6.7/7.5.4, FortiClient Windows 7.4.7, FortiPAM Chrome Extension 8.0.1.123, FortiMonitorOnSight 7.2.8). Given the breadth of affected products—including management, security orchestration, and endpoint platforms—organizations should treat this as a priority patch cycle even absent confirmed in-the-wild exploitation, given Fortinet products' history of being targeted post-disclosure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-22575, CVE-2026-26084, CVE-2026-84385, CVE-2026-84386, CVE-2026-84387, CVE-2026-84388, CVE-2026-84389, CVE-2026-84390, CVE-2026-84391, CVE-2026-84392, CVE-2026-84393

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1166

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/049d90d5-3f7c-5de8-b202-eae726251c0e/anssi-flags-multiple-fortinet-product-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
