Fortinet FortiOS 7.6
Vulnerabilities, fixed releases, vendor recommendation and support status of the 7.6 branch, from official sources.
Patcharo matches 22 vulnerabilities against Fortinet FortiOS 7.6: 4 critical, 4 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 10 Sept 2026.
Last verified by Patcharo: 30 Sept 2026 at 12:17 UTC
In brief
- Matched CVEs
- 22
- CISA KEV
- 4
- Newest fix stated
- none stated
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 15 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Recommended release per model
The vendor states one recommended release per hardware model (91 models); models are grouped by recommended release.
Vendor wording: “Recommended Release Version” · vendor statement dated 1 Jun 2026
- 7.6.6
- FortiGate-40F, FortiGate-40F-3G4G, FortiGate-50G/51G and variants, FortiGate-60F, FortiGate-61F, FortiGate-70F, FortiGate-70G/71G and variants, FortiGate-71F, FortiGate-80F, FortiGate-81F, FortiGate-90G, FortiGate-91G, FortiGate-100F, FortiGate-101F, FortiGate-120G, FortiGate-121G, FortiGate-200E, FortiGate-200F, FortiGate-200G/201G, FortiGate-201E, FortiGate-201F, FortiGate-300E, FortiGate-301E, FortiGate-400E, FortiGate-400E-BYPASS, FortiGate-400F, FortiGate-401E, FortiGate-401F, FortiGate-500E, FortiGate-501E, FortiGate-600E, FortiGate-600F, FortiGate-601E, FortiGate-601F, FortiGate-800D, FortiGate-900D, FortiGate-900G, FortiGate-901G, FortiGate-1000D, FortiGate-1000F, FortiGate-1001F, FortiGate-1100E, FortiGate-1101E, FortiGate-1800F, FortiGate-1801F, FortiGate-2000E, FortiGate-2200E, FortiGate-2201E, FortiGate-2500E, FortiGate-2600F, FortiGate-2601F, FortiGate-3000D, FortiGate-3000F, FortiGate-3001F, FortiGate-3100D, FortiGate-3200D, FortiGate-3200F, FortiGate-3201F, FortiGate-3300E, FortiGate-3301E, FortiGate-3400E, FortiGate-3401E, FortiGate-3500F, FortiGate-3501F, FortiGate-3600E, FortiGate-3601E, FortiGate-3700D, FortiGate-3700F, FortiGate-3701F, FortiGate-3960E, FortiGate-3980E, FortiGate-4200F, FortiGate-4201F, FortiGate-4400F, FortiGate-4401F, FortiGate-4800F, FortiGate-4801F, FortiGate-5001E, FortiGate-5001E1, FortiGate-6000F / 7000E / 7000F, FortiGate-VM64 - all versions, FortiGateRugged-60F, FortiGateRugged-60F-3G4G, FortiGateRugged-70F, FortiGateRugged-70F-3G4G, FortiWiFi-40F, FortiWiFi-40F-3G4G, FortiWiFi-50G/51G and variants, FortiWiFi-60F, FortiWiFi-61F, FortiWiFi-70G/71G and variants
Source: Technical Tip: Recommended release for FortiOS (as of June 2026)last verified by Patcharo 30 Sept 2026 at 00:17 UTC
Vulnerabilities affecting 7.6
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2026-71407 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 m… | High8.1CVSS 3.1, High | after 7.6.6 | |
| CVE-2025-53844 A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, For… | High8.8CVSS 3.1, High | after 7.6.3 | |
| CVE-2025-53847 A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… | High8.8CVSS 3.1, High | after 7.6.3 | |
| CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Medium5.9CVSS 3.1, MediumKEV | after 7.6.1 | |
| CVE-2025-64157 A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7… | High7.2CVSS 3.1, High | after 7.6.4 | |
| CVE-2026-22153 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 … | High8.1CVSS 3.1, High | after 7.6.4 | |
| CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.6.5 | |
| CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.6.2 | |
| CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.6.3 | |
| CVE-2025-53843 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.… | High7.5CVSS 3.1, High | after 7.6.3 | |
| CVE-2025-58413 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.… | High7.5CVSS 3.1, High | after 7.6.3 | |
| CVE-2024-50571 A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0… | High7.2CVSS 3.1, High | No fix stated | |
| CVE-2025-22258 A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1… | High7.2CVSS 3.1, High | after 7.6.2 | |
| CVE-2025-25253 An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 … | High7.5CVSS 3.1, High | after 7.6.2 | |
| CVE-2025-57740 An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and b… | High8.8CVSS 3.1, High | after 7.6.2 | |
| CVE-2025-53744 An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.… | High7.2CVSS 3.1, High | after 7.6.2 | |
| CVE-2024-52965 A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7… | High7.2CVSS 3.1, High | after 7.6.1 | |
| CVE-2025-22254 An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.… | High7.2CVSS 3.1, High | after 7.6.1 | |
| CVE-2025-22252 A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwit… | High7.2CVSS 3.1, High | No fix stated | |
| CVE-2024-40591 An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.… | High7.2CVSS 3.1, High | No fix stated | |
| CVE-2024-48884 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo… | Critical9.1CVSS 3.1, Critical | No fix stated | |
| CVE-2024-46670 An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.… | High7.5CVSS 3.1, High | No fix stated |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Advisory (AVI)CERTFR-2026-AVI-1015Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2026
- Advisory (AVI)CERTFR-2026-AVI-0575Multiples vulnérabilités dans les produits FortinetPublished 13 May 2026
- Advisory (AVI)CERTFR-2026-AVI-0440Multiples vulnérabilités dans les produits FortinetPublished 15 Apr 2026
- Advisory (AVI)CERTFR-2026-AVI-0147Multiples vulnérabilités dans les produits FortinetPublished 11 Feb 2026
- Advisory (AVI)CERTFR-2026-AVI-0097Vulnérabilité dans les produits FortinetPublished 28 Jan 2026
- Advisory (AVI)CERTFR-2026-AVI-0035Multiples vulnérabilités dans les produits FortinetPublished 14 Jan 2026
- Advisory (AVI)CERTFR-2025-AVI-1084Multiples vulnérabilités dans les produits FortinetPublished 10 Dec 2025
- Advisory (AVI)CERTFR-2025-AVI-1023Multiples vulnérabilités dans les produits FortinetPublished 19 Nov 2025
- Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
- Advisory (AVI)CERTFR-2025-AVI-0679Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2025
- Advisory (AVI)CERTFR-2025-AVI-0575Multiples vulnérabilités dans les produits FortinetPublished 9 Jul 2025
- Advisory (AVI)CERTFR-2025-AVI-0496Multiples vulnérabilités dans les produits FortinetPublished 11 Jun 2025
- Advisory (AVI)CERTFR-2025-AVI-0399Multiples vulnérabilités dans les produits FortinetPublished 13 May 2025
- Advisory (AVI)CERTFR-2025-AVI-0120Multiples vulnérabilités dans les produits FortinetPublished 12 Feb 2025
- Advisory (AVI)CERTFR-2025-AVI-0031Multiples vulnérabilités dans les produits FortinetPublished 15 Jan 2025
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.