Skip to content

Fortinet FortiManager 7.0

Vulnerabilities, fixed releases, vendor recommendation and support status of the 7.0 branch, from official sources.

Patcharo matches 24 vulnerabilities against Fortinet FortiManager 7.0: 8 critical, 2 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 8 Jul 2026.

Last verified by Patcharo: 30 Sept 2026 at 15:17 UTC

In brief

Matched CVEs
24
CISA KEV
2
Newest fix stated
none stated
Support
No statement in the catalog
Recommended maintenance build
No official recommendation
Recommended release
No official recommendation
CERT-FR
10 documents

Support status

From the vendor's published life-cycle policy; support is not a recommendation.

The life-cycle policy Patcharo reads states nothing about this branch.

Vendor recommendation

The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.

Fortinet publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.

Vulnerabilities affecting 7.0

Each record matched to this branch with the fixed release the source states, newest first.

CVESeverityFixed inPublished
CVE-2025-48418

A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 throu…

High7.2CVSS 3.1, Highafter 7.0.14
CVE-2025-68648

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, For…

High7.2CVSS 3.1, Highafter 7.0.16
CVE-2026-24858

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Critical9.8CVSS 3.1, CriticalKEVafter 7.0.15
CVE-2024-50571

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0…

High7.2CVSS 3.1, Highafter 7.0.13
CVE-2024-26013

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…

High7.5CVSS 3.1, Highafter 7.0.11
CVE-2023-25610

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve…

Critical9.8CVSS 3.1, Criticalafter 7.0.4
CVE-2024-40584

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability […

High7.2CVSS 3.1, Highafter 7.0.13
CVE-2024-33504

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0…

High7.7CVSS 3.1, Highafter 7.0.13
CVE-2024-45331

A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7…

High7.8CVSS 3.1, Highafter 7.0.16
CVE-2024-47571

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows a…

Critical9.8CVSS 3.1, Criticalafter 7.0.8
CVE-2024-35277

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiMan…

High7.5CVSS 3.1, Highafter 7.0.12
CVE-2024-33502

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, F…

High7.2CVSS 3.1, Highafter 7.0.13
CVE-2024-33503

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManage…

High7.8CVSS 3.1, Highafter 7.0.16
CVE-2024-35276

A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.…

Critical9.8CVSS 3.1, Criticalafter 7.0.12
CVE-2024-36512

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, F…

High7.2CVSS 3.1, Highafter 7.0.12
CVE-2021-32589

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.…

Critical9.8CVSS 3.1, CriticalNo fix stated
CVE-2024-48889

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability […

High7.2CVSS 3.1, Highafter 7.0.12
CVE-2024-33505

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.…

High7.3CVSS 3.1, Highafter 7.0.13
CVE-2024-26011

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 th…

Critical9.8CVSS 3.1, Criticalafter 7.0.11
CVE-2024-23666

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 an…

High8.8CVSS 3.1, Highafter 7.0.11
CVE-2024-47575

Fortinet FortiManager Missing Authentication Vulnerability

Critical9.8CVSS 3.1, CriticalKEVafter 7.0.12
CVE-2024-21757

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7…

High7.8CVSS 3.1, Highafter 7.0.10
CVE-2023-36554

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 …

Critical9.8CVSS 3.1, Criticalafter 7.0.10
CVE-2023-42791

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.…

High8.8CVSS 3.1, Highafter 7.0.8

CERT-FR advisories and alerts

Documents of the French national CERT referencing these CVEs, newest first.

  • Advisory (AVI)CERTFR-2026-AVI-0265Multiples vulnérabilités dans les produits FortinetPublished 11 Mar 2026
  • Advisory (AVI)CERTFR-2026-AVI-0097Vulnérabilité dans les produits FortinetPublished 28 Jan 2026
  • Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
  • Advisory (AVI)CERTFR-2025-AVI-0293Multiples vulnérabilités dans les produits FortinetPublished 9 Apr 2025
  • Advisory (AVI)CERTFR-2025-AVI-0120Multiples vulnérabilités dans les produits FortinetPublished 12 Feb 2025
  • Advisory (AVI)CERTFR-2025-AVI-0031Multiples vulnérabilités dans les produits FortinetPublished 15 Jan 2025
  • Advisory (AVI)CERTFR-2024-AVI-1096Multiples vulnérabilités dans les produits FortinetPublished 19 Dec 2024
  • Advisory (AVI)CERTFR-2024-AVI-0979Multiples vulnérabilités dans les produits FortinetPublished 13 Nov 2024
  • Alert (ALE)CERTFR-2024-ALE-014[MàJ] Multiples vulnérabilités dans Fortinet FortiManagerPublished 23 Oct 2024 · updated 31 Mar 2025 · closed 31 Mar 2025
  • Advisory (AVI)CERTFR-2024-AVI-0917Vulnérabilité dans Fortinet FortiManagerPublished 23 Oct 2024 · updated 24 Oct 2024

How Patcharo reads this

Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.

Read the methodology

Other FortiManager branches

All FortiManager vulnerabilities and branches

Official sources