VORANT. Threat Intelligence Sign in Get the full feed

Fortinet patches 28 flaws, CVE-2025-61624 exploited

high vulnerability technologyfinancial-serviceshealthcaregovernment-nationaltelecommunicationsinfrastructure

Fortinet patched 28 vulnerabilities across 14 product lines; CVE-2025-61624, a path-traversal flaw allowing arbitrary file write/delete, is exploited in the wild.

Fortinet released patches for 28 vulnerabilities affecting FortiAnalyzer, FortiClientEMS, FortiDDoS, FortiManager, FortiNAC-F, FortiNDR, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiSOAR, FortiSwitchManager, FortiVoice, and FortiWeb. The most critical flaws include CVE-2026-22828 (heap-based buffer overflow in FortiAnalyzer Cloud's oftpd daemon enabling unauthenticated remote code execution), CVE-2026-39808 (OS command injection in FortiSandbox), CVE-2026-39813 (path-traversal authentication bypass in FortiSandbox), and CVE-2026-39809 (SQL injection in FortiClientEMS). These vulnerabilities allow unauthenticated or low-privileged attackers to execute arbitrary code, bypass authentication, or manipulate databases.

CVE-2025-61624, a path-traversal vulnerability in FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager command-line interfaces, has been exploited in the wild. This flaw allows privileged attackers to write or delete arbitrary files via crafted CLI arguments. Additional vulnerabilities include SQL injection flaws in FortiAnalyzer/FortiManager (CVE-2025-61848) and FortiDDoS-F (CVE-2026-39815), credential-exposure issues in FortiSOAR, and cross-site scripting weaknesses in FortiSandbox and FortiSOAR. The advisory emphasizes immediate patching, least-privilege principles, network segmentation, and vulnerability scanning to mitigate exposure across the extensive attack surface created by these widely-deployed enterprise security products.

Mentioned in this report

Vulnerabilities CVE-2024-23104CVE-2025-53847CVE-2025-59809CVE-2025-61624CVE-2025-61848CVE-2025-61886CVE-2025-68649CVE-2026-21741CVE-2026-21742CVE-2026-22154CVE-2026-22155CVE-2026-22573CVE-2026-22574CVE-2026-22576CVE-2026-22828CVE-2026-23708CVE-2026-25691CVE-2026-27316CVE-2026-39808KEVCVE-2026-39809CVE-2026-39810CVE-2026-39811CVE-2026-39812CVE-2026-39813CVE-2026-39814CVE-2026-39815

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-arbitrary-code-execution_2026-035

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free