Skip to content

Fortinet FortiOS 5.6

Vulnerabilities, fixed releases, vendor recommendation and support status of the 5.6 branch, from official sources.

Patcharo matches 5 vulnerabilities against Fortinet FortiOS 5.6: 2 critical, 1 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 17 Jun 2026.

Last verified by Patcharo: 29 Sept 2026 at 12:17 UTC

In brief

Matched CVEs
5
CISA KEV
1
Newest fix stated
none stated
Support
No statement in the catalog
Recommended maintenance build
No official recommendation
Recommended release
No official recommendation
CERT-FR
0 documents

Support status

From the vendor's published life-cycle policy; support is not a recommendation.

The life-cycle policy Patcharo reads states nothing about this branch.

Vendor recommendation

The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.

Vulnerabilities affecting 5.6

Each record matched to this branch with the fixed release the source states, newest first.

CVESeverityFixed inPublished
CVE-2023-25610

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve…

Critical9.8CVSS 3.1, Criticalafter 5.6.14
CVE-2020-12820

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5…

High8.8CVSS 3.1, Highafter 5.6.12
CVE-2020-12819

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate v…

High7.5CVSS 3.1, Highafter 5.6.12
CVE-2023-29181

A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6…

High8.8CVSS 3.1, Highafter 5.6.14
CVE-2022-42475

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Critical9.8CVSS 3.1, CriticalKEVRansomwareafter 5.6.14

How Patcharo reads this

Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.

Read the methodology

Other FortiOS branches

All FortiOS vulnerabilities and branches

Official sources