Exploited CVEs / By vendor / Fortinet

Fortinet vulnerabilities actively exploited

29 Fortinet CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2025-68686 (FortiOS, added 2026-07-27). 14 of the 29 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

29 exploited CVEs14 ransomware-linked
Senserva AI Opinion and rich prompt for Fortinet exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

FortiOS: 9 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-68686FortiOS2026-07-27CVSS 5.9, EPSS 1%
CVE-2019-6693FortiOS2025-06-25ransomware, CVSS 6.5, EPSS 6%
CVE-2024-21762FortiOS2024-02-09ransomware, CVSS 9.8, EPSS 84%
CVE-2022-41328FortiOS2023-03-14CVSS 7.1, EPSS 12%
CVE-2022-42475FortiOS2022-12-13ransomware, CVSS 9.8, EPSS 99%
CVE-2021-44168FortiOS2021-12-10CVSS 7.8, EPSS 1%
CVE-2018-13379FortiOS2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2019-5591FortiOS2021-11-03ransomware, CVSS 6.5, EPSS 18%
CVE-2020-12812FortiOS2021-11-03ransomware, CVSS 9.8, EPSS 49%

Multiple Products: 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-24858Multiple Products2026-01-27CVSS 9.8, EPSS 86%
CVE-2025-59718Multiple Products2025-12-16CVSS 9.8, EPSS 63%
CVE-2025-32756Multiple Products2025-05-14CVSS 9.8, EPSS 30%
CVE-2024-23113Multiple Products2024-10-09CVSS 9.8, EPSS 62%
CVE-2022-40684Multiple Products2022-10-11ransomware, CVSS 9.8, EPSS 100%

FortiOS and FortiProxy: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-24472FortiOS and FortiProxy2025-03-18ransomware, CVSS 8.1, EPSS 4%
CVE-2024-55591FortiOS and FortiProxy2025-01-14ransomware, CVSS 9.8, EPSS 98%
CVE-2018-13382FortiOS and FortiProxy2022-01-10ransomware, CVSS 7.5, EPSS 82%
CVE-2018-13383FortiOS and FortiProxy2022-01-10ransomware, CVSS 6.5, EPSS 34%

FortiClient EMS: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-21643FortiClient EMS2026-04-13CVSS 9.8, EPSS 94%
CVE-2026-35616FortiClient EMS2026-04-06CVSS 9.8, EPSS 89%
CVE-2023-48788FortiClient EMS2024-03-25ransomware, CVSS 9.8, EPSS 98%

FortiWeb: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-58034FortiWeb2025-11-18CVSS 7.2, EPSS 56%
CVE-2025-64446FortiWeb2025-11-14CVSS 9.8, EPSS 92%
CVE-2025-25257FortiWeb2025-07-18CVSS 9.8, EPSS 97%

Other Fortinet products

CVEProductAdded to KEVSignals
CVE-2026-25089FortiSandbox2026-07-16CVSS 9.8, EPSS 74%
CVE-2026-39808FortiSandbox2026-07-16CVSS 9.8, EPSS 91%
CVE-2024-47575FortiManager2024-10-23CVSS 9.8, EPSS 95%
CVE-2023-27997FortiOS and FortiProxy SSL-VPN2023-06-13ransomware, CVSS 9.8, EPSS 86%
CVE-2018-13374FortiOS and FortiADC2022-09-08ransomware, CVSS 4.3, EPSS 38%

Common questions about exploited Fortinet CVEs

Which Fortinet vulnerabilities are actively exploited?

As of August 2026, 29 Fortinet CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are FortiOS (9), Multiple Products (5), FortiOS and FortiProxy (4), FortiClient EMS (3). 14 are linked to ransomware campaigns.

What is the newest exploited Fortinet CVE?

CVE-2025-68686, affecting FortiOS, added to the CISA KEV catalog on 2026-07-27. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Fortinet CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Fortinet CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Fortinet KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.