Known vulnerabilities in Fortinet, Inc FortiAuthenticator

Vendor: Fortinet, Inc
Website: https://www.fortinet.com/
Total Security Bulletins: 16

Security bulletins (16)

Secuity bulletin Severity Status Published
SB2025120960: Direct Request ('Forced Browsing') in FortiAuthenticator Low
Patched
09.12.2025
SB2025120956: Improper access control in FortiAuthenticator Low
Patched
09.12.2025
SB2024101441: FortiAuthenticator update for OpenSSH regreSSHion attack High
Patched Public exploit
14.10.2024
SB2024051537: Open redirect in FortiAuthenticator Low
Patched
15.05.2024
SB2023041212: Fortinet products update for Linux kernel Low
Patched Exploited
12.04.2023
SB2023041203: Denial of service in FortiAuthenticator, FortiDeceptor and FortiMail Low
Patched
12.04.2023
SB2023041193: Reflected XSS in FortiAuthenticator Medium
Patched
11.04.2023
SB2023021715: Disclosure of private keys for 2FA in FortiOS and FortiAuthenticator Low
Patched
17.02.2023
SB2022040423: Denial of service in FortiAuthenticator OpenSSL library Medium
Patched
04.04.2022
SB2022020175: Improper access control in FortiAuthenticator Low
Patched
01.02.2022
SB2021090716: Privilege escalation in FortiAuthenticator Low
Patched
07.09.2021
SB2021080316: Denial of service in FortiAuthenticator Medium
Patched
03.08.2021
SB2021060139: Hard-coded cryptographic key in FortiAuthenticator Low
Patched
01.06.2021
SB2020010803: Cross-site scripting in Fortinet FortiAuthenticator Low
Patched
08.01.2020
SB2018060114: Cross-site scripting in Fortinet, FortiAuthenticator Low
Patched
01.06.2018
SB2015020303: Multiple vulnerabilities in Fortinet, FortiAuthenticator High
Patched
03.02.2015