CVE-2025-55018
CVE-2025-52436, with a CVSS score of 8.8 (High), is an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FortiSandbox which may allow an unauthenticated attacker to execute commands via crafted requests. CVE-2026-22153, having a CVSS score of 8.1, is an Authentication Bypass by Primary Weakness vulnerability in FortiOS fnbamd. Its exploitation may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. CVE-2025-68686, with a CVSS score of 5.9, is an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in FortiOS SSL-VPN which may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. UPDATE (2026-07-28) CISA added CVE-2025-68686 to its KEV list indicating active exploitation. The critical vulnerability previously patched, CVE-2026-21643, is an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS which may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
EPSS 0.35% · 27.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| FortiOS | FortiOS 7.2.0 through 7.2.11 | |
| FortiOS | FortiOS 7.0 all versions | |
| FortiSandbox | FortiSandbox 4.2 all versions | |
| FortiAuthenticator | FortiAuthenticator 6.3 all versions | |
| FortiOS | FortiOS 7.6.0 through 7.6.4 | |
| FortiAuthenticator | FortiAuthenticator 6.6.0 through 6.6.6 | |
| FortiOS | FortiOS 7.4.0 through 7.4.9 | |
| FortiClientEMS | FortiClientEMS 7.4.4 | |
| Microsoft | FortiClientWindows 7.0 all versions | |
| FortiOS | FortiOS 6.4 all versions | |
| FortiSandbox | FortiSandbox 5.0.0 through 5.0.1 | |
| Microsoft | FortiClientWindows 7.2.0 through 7.2.12 | |
| FortiOS | FortiOS 7.2 all versions | |
| Microsoft | FortiClientWindows 7.4.0 through 7.4.4 | |
| FortiAuthenticator | FortiAuthenticator 6.4 all versions | |
| FortiSandbox | FortiSandbox 4.0 all versions | |
| FortiOS | FortiOS 7.4.0 through 7.4.6 | |
| FortiSandbox | FortiSandbox 4.4.0 through 4.4.7 | |
| FortiAuthenticator | FortiAuthenticator 6.5 all versions |
Timeline
- Aug 5, 2025 CVE ID Reserved
- Feb 10, 2026 CVE Published
- Feb 10, 2026 PoC Published
- Feb 10, 2026 PoC Published
- Feb 11, 2026 EPSS Score
- Feb 11, 2026 PoC Published
- Feb 11, 2026 PoC Published
- Feb 11, 2026 PoC Published
- Feb 13, 2026 EPSS Score
- Feb 14, 2026 PoC Published
- Feb 15, 2026 EPSS Score
- Feb 17, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-were-patched-fortinet-products-patch-immediately advisory
- https://fortiguard.fortinet.com/psirt technical
- https://www.fortiguard.com/psirt/FG-IR-25-661 technical
- https://www.fortiguard.com/psirt/FG-IR-25-384 technical
- https://www.fortiguard.com/psirt/FG-IR-25-795 technical
- https://www.fortiguard.com/psirt/FG-IR-25-1052 technical
- https://www.fortiguard.com/psirt/FG-IR-25-528 technical
- https://www.fortiguard.com/psirt/FG-IR-25-667 technical
- https://www.fortiguard.com/psirt/FG-IR-25-934 technical
- https://www.fortiguard.com/psirt/FG-IR-25-093 technical
- https://www.fortiguard.com/psirt/FG-IR-25-1142 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-22153 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21743 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21643 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-68686 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-64157 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-62676 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-62439 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-55018 technical
- https://nvd.nist.gov/vuln/detail/CVE-2025-52436 technical