Fortinet FortiManager 7.6
Vulnerabilities, fixed releases, vendor recommendation and support status of the 7.6 branch, from official sources.
Patcharo matches 13 vulnerabilities against Fortinet FortiManager 7.6: 4 critical, 2 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 8 Sept 2026.
Last verified by Patcharo: 30 Sept 2026 at 12:17 UTC
In brief
- Matched CVEs
- 13
- CISA KEV
- 2
- Newest fix stated
- none stated
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 11 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Fortinet publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.
Vulnerabilities affecting 7.6
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2026-70468 A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, Fort… | High8.1CVSS 3.1, High | No fix stated | |
| CVE-2025-61848 An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fort… | High7.2CVSS 3.1, High | after 7.6.3 | |
| CVE-2025-48418 A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 throu… | High7.2CVSS 3.1, High | after 7.6.3 | |
| CVE-2026-22572 An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 thr… | High7.2CVSS 3.1, High | after 7.6.3 | |
| CVE-2025-68648 A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, For… | High7.2CVSS 3.1, High | after 7.6.4 | |
| CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.6.5 | |
| CVE-2024-50571 A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0… | High7.2CVSS 3.1, High | after 7.6.1 | |
| CVE-2024-33504 A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0… | High7.7CVSS 3.1, High | after 7.6.1 | |
| CVE-2024-50563 A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 throu… | Critical9.8CVSS 3.1, Critical | after 7.6.1 | |
| CVE-2024-48884 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo… | Critical9.1CVSS 3.1, Critical | after 7.6.1 | |
| CVE-2024-50566 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in… | High8.8CVSS 3.1, High | after 7.6.1 | |
| CVE-2024-48889 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [… | High7.2CVSS 3.1, High | No fix stated | |
| CVE-2024-47575 Fortinet FortiManager Missing Authentication Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | No fix stated |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Advisory (AVI)CERTFR-2026-AVI-1015Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2026
- Advisory (AVI)CERTFR-2026-AVI-0440Multiples vulnérabilités dans les produits FortinetPublished 15 Apr 2026
- Advisory (AVI)CERTFR-2026-AVI-0265Multiples vulnérabilités dans les produits FortinetPublished 11 Mar 2026
- Advisory (AVI)CERTFR-2026-AVI-0097Vulnérabilité dans les produits FortinetPublished 28 Jan 2026
- Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
- Advisory (AVI)CERTFR-2025-AVI-0120Multiples vulnérabilités dans les produits FortinetPublished 12 Feb 2025
- Advisory (AVI)CERTFR-2025-AVI-0031Multiples vulnérabilités dans les produits FortinetPublished 15 Jan 2025
- Advisory (AVI)CERTFR-2025-AVI-0030Multiples vulnérabilités dans les produits FortinetPublished 14 Jan 2025 · updated 12 Feb 2025
- Advisory (AVI)CERTFR-2024-AVI-1096Multiples vulnérabilités dans les produits FortinetPublished 19 Dec 2024
- Alert (ALE)CERTFR-2024-ALE-014[MàJ] Multiples vulnérabilités dans Fortinet FortiManagerPublished 23 Oct 2024 · updated 31 Mar 2025 · closed 31 Mar 2025
- Advisory (AVI)CERTFR-2024-AVI-0917Vulnérabilité dans Fortinet FortiManagerPublished 23 Oct 2024 · updated 24 Oct 2024
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.