Fortinet patches RCE flaws in FortiOS, FortiProxy, FortiSandbox
Multiple vulnerabilities in Fortinet products allow remote code execution and data confidentiality breaches across FortiOS, FortiProxy, FortiPortal, and FortiSandbox platforms.
France's CERT has issued an advisory regarding multiple security vulnerabilities affecting a wide range of Fortinet products. The flaws impact FortiOS versions 7.2.x through 7.6.x, FortiProxy versions 7.2.x through 7.6.x, FortiPortal versions up to 7.4.x, and various FortiSandbox deployments including Cloud and PaaS editions. The vulnerabilities enable remote attackers to execute arbitrary code and compromise data confidentiality.
Fortinet has released patches addressing three distinct CVEs: CVE-2025-67862, CVE-2026-25089, and CVE-2026-49938. The advisory references three separate Fortinet security bulletins (FG-IR-26-140, FG-IR-26-141, and FG-IR-26-143) published on June 9, 2026. Organizations running affected versions should prioritize patching to FortiOS 7.2.11+, 7.4.8+, or 7.6.3+; FortiProxy 7.2.15+, 7.4.11+, or 7.6.4+; FortiPortal 7.2.9+ or 7.4.8+; and FortiSandbox 4.4.9+ or 5.0.6+ depending on their deployment.
The affected products are widely deployed in enterprise network security architectures, making these vulnerabilities particularly significant for organizations relying on Fortinet infrastructure for perimeter defense, SSL inspection, and threat analysis. Given the remote code execution capability, these flaws represent a critical attack surface that threat actors may seek to exploit.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0725
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free