VDB

CVE-2025-55018

CVE-2025-55018 PUBLISHED CVSS 5.800000190734863 MEDIUM

CVE-2025-52436, with a CVSS score of 8.8 (High), is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox which may allow an unauthenticated attacker to execute commands via crafted requests. CVE-2026-22153, having a CVSS score of 8.1, is an Authentication Bypass by Primary Weakness vulnerability in FortiOS fnbamd. Its exploitation may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. CVE-2025-68686, with a CVSS score of 5.9, is an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in FortiOS SSL-VPN which may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. UPDATE (2026-07-28) CISA added CVE-2025-68686 to its KEV list indicating active exploitation. The critical vulnerability previously patched, CVE-2026-21643, is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS which may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

EPSS 0.35% · 27.8th percentile

Risk Scores

CVSS 3.1
5.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.35%
27.8th percentile

Affected Products

VendorProductVersions
FortiOSFortiOS 7.2.0 through 7.2.11
FortiOSFortiOS 7.0 all versions
FortiSandboxFortiSandbox 4.2 all versions
FortiAuthenticatorFortiAuthenticator 6.3 all versions
FortiOSFortiOS 7.6.0 through 7.6.4
FortiAuthenticatorFortiAuthenticator 6.6.0 through 6.6.6
FortiOSFortiOS 7.4.0 through 7.4.9
FortiClientEMSFortiClientEMS 7.4.4
MicrosoftFortiClientWindows 7.0 all versions
FortiOSFortiOS 6.4 all versions
FortiSandboxFortiSandbox 5.0.0 through 5.0.1
MicrosoftFortiClientWindows 7.2.0 through 7.2.12
FortiOSFortiOS 7.2 all versions
MicrosoftFortiClientWindows 7.4.0 through 7.4.4
FortiAuthenticatorFortiAuthenticator 6.4 all versions
FortiSandboxFortiSandbox 4.0 all versions
FortiOSFortiOS 7.4.0 through 7.4.6
FortiSandboxFortiSandbox 4.4.0 through 4.4.7
FortiAuthenticatorFortiAuthenticator 6.5 all versions

Timeline

  • Aug 5, 2025 CVE ID Reserved
  • Feb 10, 2026 CVE Published
  • Feb 10, 2026 PoC Published
  • Feb 10, 2026 PoC Published
  • Feb 11, 2026 EPSS Score
  • Feb 11, 2026 PoC Published
  • Feb 11, 2026 PoC Published
  • Feb 11, 2026 PoC Published
  • Feb 13, 2026 EPSS Score
  • Feb 14, 2026 PoC Published
  • Feb 15, 2026 EPSS Score
  • Feb 17, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›