Known vulnerabilities in Fortinet, Inc FortiOS 7.4.5

Vendor: Fortinet, Inc
Website: https://www.fortinet.com/
Total Security Bulletins: 32

Security bulletins (32)

Secuity bulletin Severity Status Published
SB2026012392: FortiCloud SSO login authentication bypass in Fortinet products Critical
Patched Exploited
23.01.2026
SB2026011365: Remote code execution in FortiOS and FortiSwitchManager cw_acd daemo Critical
Patched
13.01.2026
SB2025121064: FortiCloud SSO login authentication bypass in Fortinet products Critical
Patched Exploited
10.12.2025
SB2025111874: Stack buffer overflow in FortiOS CAPWAP daemon Medium
Patched
18.11.2025
SB2025111873: Improper privilege management in Fortinet products Low
Patched
18.11.2025
SB2025111871: Buffer underflow in FortiOS Low
Patched
18.11.2025
SB2025102162: Multiple vulnerabilities in Fortinet FortiOS, FortiProxy and FortiSASE Low
Patched
21.10.2025
SB2025101575: Improper validation of certificate with host mismatch in FortiOS and FortiProxy Medium
Patched
15.10.2025
SB2025101567: Unchecked Return Value in FortiOS Low
Patched
15.10.2025
SB2025101565: Incorrect provision of specified functionality in FortiOS Low
Patched
15.10.2025
SB2025101505: Inclusion of Sensitive Information in Log Files in FortiOS and FortiProxy Low
Patched
15.10.2025
SB2025101504: Insufficient Session Expiration in FortiOS Medium
Patched
15.10.2025
SB2025101503: Heap-based buffer overflow in Fortinet products Low
Patched
15.10.2025
SB20251014108: Heap-based buffer overflow in Fortinet products Medium
Patched
14.10.2025
SB20251014106: Heap-based buffer overflow in Fortinet products Low
Patched
14.10.2025
SB20250812105: Incorrect Privilege Assignment in FortiOS Low
Patched
12.08.2025
SB2025081299: Integer overflow in Fortinet products Low
Patched
12.08.2025
SB2025070845: Heap-based buffer overflow in FortiOS Low
Patched
08.07.2025
SB2025070844: Missing critical step in authentication in FortiOS and FortiProxy Low
Patched
08.07.2025
SB2025070843: Improperly implemented security check for standard in FortiOS and FortiProxy Medium
Patched
08.07.2025
SB2025061119: Improper privilege management in Fortinet products Low
Patched
11.06.2025
SB2025061116: Improper certificate validation in FortiOS Low
Patched
11.06.2025
SB2025061115: Authentication bypass using an alternate path or channel in FortiOS and FortiProxy Low
Patched
11.06.2025
SB2025061113: Insufficient Session Expiration in FortiOS Medium
Patched
11.06.2025
SB2025061112: Improper restriction of communication channel to intended endpoints in FortiOS Low
Patched
11.06.2025
SB2025061107: Incomplete cleanup in FortiOS and FortiProxy Low
Patched
11.06.2025
SB2025061106: Information disclosure in FortiOS Low
Patched
11.06.2025
SB2025051366: Missing authentication for critical function in Fortinet products High
Patched
13.05.2025
SB2025040986: IP address spoofing in FortiOS Low
Patched
09.04.2025
SB2025040985: Authenticated denial of service in FortiOS SSL VPN Medium
Patched
09.04.2025
SB2025040963: LDAP credentials exposure in FortiOS Low
Patched
09.04.2025
SB2025012295: Remote denial of service in FortiOS IPsec Low
Patched
22.01.2025