# Fortinet released patches for multiple critical vulnerabilities across 14 products

Published: 2026-04-14 · Severity: critical · Sectors: government-national, financial-services, healthcare, education, infrastructure, telecommunications
Canonical: https://vorant.io/reports/861e5edf-b487-49de-aae6-b485db868e2f/fortinet-released-patches-for-multiple-critical-vulnerabilities-across-14

> Fortinet released patches for multiple critical vulnerabilities across 14 products; CVE-2025-61624 is actively exploited, enabling arbitrary code execution.

Fortinet disclosed multiple vulnerabilities affecting a broad range of its enterprise security products, including FortiOS, FortiManager, FortiAnalyzer, and twelve other platforms. The most severe flaws include heap-based buffer overflows, OS command injection, SQL injection, and path traversal vulnerabilities that could enable unauthenticated remote code execution. CVE-2025-61624, a path traversal flaw in FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager, has been exploited in the wild and allows privileged attackers to write or delete arbitrary files.

The vulnerabilities span initial access vectors (exploitation of public-facing applications) and post-compromise abuse of privileged functions. Several flaws require no authentication (CVE-2026-22828, CVE-2026-39808, CVE-2026-39813), while others demand authenticated access but still pose significant risk due to the privileged nature of affected services. Successful exploitation could result in full system compromise, data exfiltration, or denial of service across network management, endpoint security, and unified threat management platforms.

Organizations running affected Fortinet products face immediate risk and should prioritize patching, particularly for internet-facing instances. The breadth of affected products and the confirmed exploitation of at least one vulnerability indicate active threat-actor interest in this attack surface. MS-ISAC recommends emergency patching, network segmentation, and least-privilege enforcement to mitigate exposure.

## Mentioned in this report

- Vulnerabilities: CVE-2024-23104, CVE-2025-53847, CVE-2025-59809, CVE-2025-61624, CVE-2025-61848, CVE-2025-61886, CVE-2025-68649, CVE-2026-21741, CVE-2026-21742, CVE-2026-22154, CVE-2026-22155, CVE-2026-22573, CVE-2026-22574, CVE-2026-22576, CVE-2026-22828, CVE-2026-23708, CVE-2026-25691, CVE-2026-27316, CVE-2026-39808 (KEV), CVE-2026-39809, CVE-2026-39810, CVE-2026-39811, CVE-2026-39812, CVE-2026-39813, CVE-2026-39814, CVE-2026-39815

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-arbitrary-code-execution_2026-035

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/861e5edf-b487-49de-aae6-b485db868e2f/fortinet-released-patches-for-multiple-critical-vulnerabilities-across-14.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
