Skip to content

Fortinet FortiOS 6.4

Vulnerabilities, fixed releases, vendor recommendation and support status of the 6.4 branch, from official sources.

Patcharo matches 39 vulnerabilities against Fortinet FortiOS 6.4: 8 critical, 5 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 11 Aug 2026.

Last verified by Patcharo: 30 Sept 2026 at 15:17 UTC

In brief

Matched CVEs
39
CISA KEV
5
Newest fix stated
none stated
Support
No statement in the catalog
Recommended maintenance build
No official recommendation
Recommended release
No official recommendation
CERT-FR
12 documents

Support status

From the vendor's published life-cycle policy; support is not a recommendation.

The life-cycle policy Patcharo reads states nothing about this branch.

Vendor recommendation

The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.

Recommended release per model

The vendor states one recommended release per hardware model (1 models); models are grouped by recommended release.

Vendor wording: “Recommended Release Version” · vendor statement dated 1 Jun 2026

6.4.16
FortiGate-5001D

Source: Technical Tip: Recommended release for FortiOS (as of June 2026)last verified by Patcharo 30 Sept 2026 at 00:17 UTC

Vulnerabilities affecting 6.4

Each record matched to this branch with the fixed release the source states, newest first.

CVESeverityFixed inPublished
CVE-2025-53844

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, For…

High8.8CVSS 3.1, Highafter 6.4.16
CVE-2025-53847

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS…

High8.8CVSS 3.1, Highafter 6.4.16
CVE-2025-68686

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Medium5.9CVSS 3.1, MediumKEVafter 6.4.16
CVE-2025-53843

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.…

High7.5CVSS 3.1, Highafter 6.4.16
CVE-2025-58413

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.…

High7.5CVSS 3.1, Highafter 6.4.16
CVE-2023-46718

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0…

High7.8CVSS 3.1, Highafter 6.4.16
CVE-2024-50571

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0…

High7.2CVSS 3.1, Highafter 6.4.15
CVE-2025-57740

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and b…

High8.8CVSS 3.1, Highafter 6.4.16
CVE-2024-26009

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0…

High8.1CVSS 3.1, Highafter 6.4.15
CVE-2023-45584

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, F…

High7.2CVSS 3.1, Highafter 6.4.16
CVE-2025-53744

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.…

High7.2CVSS 3.1, Highafter 6.4.16
CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.…

High7.2CVSS 3.1, Highafter 6.4.15
CVE-2024-50565

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…

High7.5CVSS 3.1, Highafter 6.4.16
CVE-2024-26013

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…

High7.5CVSS 3.1, Highafter 6.4.15
CVE-2023-37930

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vul…

High8.8CVSS 3.1, Highafter 6.4.14
CVE-2023-25610

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve…

Critical9.8CVSS 3.1, Criticalafter 6.4.11
CVE-2024-45324

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, …

High7.2CVSS 3.1, Highafter 6.4.15
CVE-2024-40591

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.…

High7.2CVSS 3.1, Highafter 6.4.15
CVE-2024-48886

A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.…

Critical9.8CVSS 3.1, Criticalafter 6.4.15
CVE-2024-48884

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo…

Critical9.1CVSS 3.1, Criticalafter 6.4.15
CVE-2024-46668

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 thr…

High7.5CVSS 3.1, Highafter 6.4.15
CVE-2020-12819

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate v…

High7.5CVSS 3.1, Highafter 6.4.1
CVE-2024-26011

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 th…

Critical9.8CVSS 3.1, Criticalafter 6.4.15
CVE-2022-45862

An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all …

High8.8CVSS 3.1, Highafter 6.4.11
CVE-2024-26010

A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, F…

High7.5CVSS 3.1, Highafter 6.4.15
CVE-2023-46720

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0…

High7.8CVSS 3.1, Highafter 6.4.15
CVE-2024-23110

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 thr…

High7.8CVSS 3.1, Highafter 6.4.14
CVE-2023-45583

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7…

High7.2CVSS 3.1, Highafter 6.4.16
CVE-2023-44247

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileg…

High7.2CVSS 3.1, Highafter 6.4.16
CVE-2023-41677

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.1…

High8.8CVSS 3.1, Highafter 6.4.14
CVE-2024-23662

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7…

High7.5CVSS 3.1, Highafter 6.4.15
CVE-2023-42789

A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, For…

Critical9.8CVSS 3.1, Criticalafter 6.4.14
CVE-2023-42790

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.…

High8.1CVSS 3.1, Highafter 6.4.14
CVE-2023-29180

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 throu…

High7.5CVSS 3.1, Highafter 6.4.12
CVE-2023-29181

A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6…

High8.8CVSS 3.1, Highafter 6.4.12
CVE-2024-21762

Fortinet FortiOS Out-of-Bound Write Vulnerability

Critical9.8CVSS 3.1, CriticalKEVRansomwareafter 6.4.14
CVE-2023-27997

Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

Critical9.8CVSS 3.1, CriticalKEVRansomwareafter 6.4.12
CVE-2022-41328

Fortinet FortiOS Path Traversal Vulnerability

High7.1CVSS 3.1, HighKEVafter 6.4.11
CVE-2022-42475

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Critical9.8CVSS 3.1, CriticalKEVRansomwareafter 6.4.10

CERT-FR advisories and alerts

Documents of the French national CERT referencing these CVEs, newest first.

  • Advisory (AVI)CERTFR-2026-AVI-0575Multiples vulnérabilités dans les produits FortinetPublished 13 May 2026
  • Advisory (AVI)CERTFR-2026-AVI-0440Multiples vulnérabilités dans les produits FortinetPublished 15 Apr 2026
  • Advisory (AVI)CERTFR-2026-AVI-0147Multiples vulnérabilités dans les produits FortinetPublished 11 Feb 2026
  • Advisory (AVI)CERTFR-2025-AVI-1023Multiples vulnérabilités dans les produits FortinetPublished 19 Nov 2025
  • Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
  • Advisory (AVI)CERTFR-2025-AVI-0679Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2025
  • Advisory (AVI)CERTFR-2025-AVI-0496Multiples vulnérabilités dans les produits FortinetPublished 11 Jun 2025
  • Advisory (AVI)CERTFR-2025-AVI-0293Multiples vulnérabilités dans les produits FortinetPublished 9 Apr 2025
  • Advisory (AVI)CERTFR-2025-AVI-0197Multiples vulnérabilités dans les produits FortinetPublished 12 Mar 2025
  • Advisory (AVI)CERTFR-2025-AVI-0120Multiples vulnérabilités dans les produits FortinetPublished 12 Feb 2025
  • Advisory (AVI)CERTFR-2025-AVI-0031Multiples vulnérabilités dans les produits FortinetPublished 15 Jan 2025
  • Advisory (AVI)CERTFR-2024-AVI-0979Multiples vulnérabilités dans les produits FortinetPublished 13 Nov 2024

How Patcharo reads this

Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.

Read the methodology

Other FortiOS branches

All FortiOS vulnerabilities and branches

Official sources