Fortinet path traversal flaw CVE-2025-61624 exploited
Fortinet disclosed dozens of vulnerabilities across its product line, including a CLI path traversal bug (CVE-2025-61624) that is being actively exploited in the wild.
CISA/MS-ISAC issued an advisory covering a large batch of Fortinet vulnerabilities spanning FortiAnalyzer, FortiClientEMS, FortiDDoS, FortiManager, FortiNAC-F, FortiNDR, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiSOAR, FortiSwitchManager, FortiVoice, and FortiWeb. The most severe issues include a heap-based buffer overflow in FortiAnalyzer Cloud's oftpd daemon, OS command injection in FortiSandbox, and SQL injection flaws in FortiClientEMS and FortiDDoS-F, several of which are remotely exploitable without authentication and could lead to arbitrary code execution.
Fortinet has confirmed that CVE-2025-61624, a path traversal vulnerability in the CLI of FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager, is being actively exploited in the wild, allowing a privileged attacker to arbitrarily write or delete files. The remaining vulnerabilities range from authentication bypass and hard-coded cryptographic keys to cross-site scripting, SSRF, and information disclosure issues, most requiring authenticated or privileged access. Given the breadth of affected products, the presence of at least one actively exploited CVE, and unauthenticated RCE-class bugs in FortiAnalyzer and FortiSandbox, organizations running these products should prioritize patching immediately.
MS-ISAC recommends applying Fortinet's stable channel updates without delay, enforcing least-privilege on service accounts, segmenting management interfaces from the internet, and conducting regular vulnerability scanning and penetration testing against externally exposed Fortinet assets.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-fortinet-products-could-allow-for-arbitrary-code-execution_2026-035
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free