# Fortinet patches 28 flaws, CVE-2025-61624 exploited

Published: 2026-04-14 · Severity: high · Sectors: technology, financial-services, healthcare, government-national, telecommunications, infrastructure
Canonical: https://vorant.io/reports/c5bfd477-f548-59f5-ab95-b7a71acf68a9/fortinet-patches-28-flaws-cve-2025-61624-exploited

> Fortinet patched 28 vulnerabilities across 14 product lines; CVE-2025-61624, a path-traversal flaw allowing arbitrary file write/delete, is exploited in the wild.

Fortinet released patches for 28 vulnerabilities affecting FortiAnalyzer, FortiClientEMS, FortiDDoS, FortiManager, FortiNAC-F, FortiNDR, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiSOAR, FortiSwitchManager, FortiVoice, and FortiWeb. The most critical flaws include CVE-2026-22828 (heap-based buffer overflow in FortiAnalyzer Cloud's oftpd daemon enabling unauthenticated remote code execution), CVE-2026-39808 (OS command injection in FortiSandbox), CVE-2026-39813 (path-traversal authentication bypass in FortiSandbox), and CVE-2026-39809 (SQL injection in FortiClientEMS). These vulnerabilities allow unauthenticated or low-privileged attackers to execute arbitrary code, bypass authentication, or manipulate databases.

CVE-2025-61624, a path-traversal vulnerability in FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager command-line interfaces, has been exploited in the wild. This flaw allows privileged attackers to write or delete arbitrary files via crafted CLI arguments. Additional vulnerabilities include SQL injection flaws in FortiAnalyzer/FortiManager (CVE-2025-61848) and FortiDDoS-F (CVE-2026-39815), credential-exposure issues in FortiSOAR, and cross-site scripting weaknesses in FortiSandbox and FortiSOAR. The advisory emphasizes immediate patching, least-privilege principles, network segmentation, and vulnerability scanning to mitigate exposure across the extensive attack surface created by these widely-deployed enterprise security products.

## Mentioned in this report

- Vulnerabilities: CVE-2024-23104, CVE-2025-53847, CVE-2025-59809, CVE-2025-61624, CVE-2025-61848, CVE-2025-61886, CVE-2025-68649, CVE-2026-21741, CVE-2026-21742, CVE-2026-22154, CVE-2026-22155, CVE-2026-22573, CVE-2026-22574, CVE-2026-22576, CVE-2026-22828, CVE-2026-23708, CVE-2026-25691, CVE-2026-27316, CVE-2026-39808 (KEV), CVE-2026-39809, CVE-2026-39810, CVE-2026-39811, CVE-2026-39812, CVE-2026-39813, CVE-2026-39814, CVE-2026-39815

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-arbitrary-code-execution_2026-035

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c5bfd477-f548-59f5-ab95-b7a71acf68a9/fortinet-patches-28-flaws-cve-2025-61624-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
