Fortinet FortiProxy 7.2
Vulnerabilities, fixed releases, vendor recommendation and support status of the 7.2 branch, from official sources.
Patcharo matches 32 vulnerabilities against Fortinet FortiProxy 7.2: 12 critical, 8 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 8 Sept 2026.
Last verified by Patcharo: 30 Sept 2026 at 15:17 UTC
In brief
- Matched CVEs
- 32
- CISA KEV
- 8
- Newest fix stated
- none stated
- Support
- No statement in the catalog
- Recommended maintenance build
- No official recommendation
- Recommended release
- No official recommendation
- CERT-FR
- 12 documents
Support status
From the vendor's published life-cycle policy; support is not a recommendation.
The life-cycle policy Patcharo reads states nothing about this branch.
Vendor recommendation
The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.
Fortinet publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.
Vulnerabilities affecting 7.2
Each record matched to this branch with the fixed release the source states, newest first.
| CVE | Severity | Fixed in | Published |
|---|---|---|---|
| CVE-2026-71407 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 m… | High8.1CVSS 3.1, High | after 7.2.16 | |
| CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.2.15 | |
| CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.2.14 | |
| CVE-2023-46718 A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0… | High7.8CVSS 3.1, High | after 7.2.15 | |
| CVE-2024-50571 A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0… | High7.2CVSS 3.1, High | after 7.2.12 | |
| CVE-2025-25253 An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 … | High7.5CVSS 3.1, High | after 7.2.15 | |
| CVE-2025-57740 An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and b… | High8.8CVSS 3.1, High | after 7.2.15 | |
| CVE-2024-26009 An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0… | High8.1CVSS 3.1, High | after 7.2.8 | |
| CVE-2023-45584 A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, F… | High7.2CVSS 3.1, High | after 7.2.7 | |
| CVE-2024-52965 A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7… | High7.2CVSS 3.1, High | after 7.2.13 | |
| CVE-2024-26013 A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For… | High7.5CVSS 3.1, High | after 7.2.9 | |
| CVE-2023-37930 Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vul… | High8.8CVSS 3.1, High | after 7.2.6 | |
| CVE-2023-25610 A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve… | Critical9.8CVSS 3.1, Critical | after 7.2.2 | |
| CVE-2024-45324 A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, … | High7.2CVSS 3.1, High | after 7.2.12 | |
| CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | High8.1CVSS 3.1, HighKEVRansomware | after 7.2.12 | |
| CVE-2024-48886 A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.… | Critical9.8CVSS 3.1, Critical | after 7.2.10 | |
| CVE-2024-48884 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo… | Critical9.1CVSS 3.1, Critical | after 7.2.11 | |
| CVE-2024-46670 An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.… | High7.5CVSS 3.1, High | after 7.2.11 | |
| CVE-2024-55591 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Critical9.8CVSS 3.1, CriticalKEVRansomware | after 7.2.12 | |
| CVE-2024-26011 A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 th… | Critical9.8CVSS 3.1, Critical | after 7.2.9 | |
| CVE-2022-45862 An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all … | High8.8CVSS 3.1, High | after 7.2.11 | |
| CVE-2024-26010 A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, F… | High7.5CVSS 3.1, High | after 7.2.9 | |
| CVE-2023-45583 A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7… | High7.2CVSS 3.1, High | after 7.2.4 | |
| CVE-2023-41677 A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.1… | High8.8CVSS 3.1, High | after 7.2.7 | |
| CVE-2023-42789 A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, For… | Critical9.8CVSS 3.1, Critical | after 7.2.6 | |
| CVE-2023-42790 A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.… | High8.1CVSS 3.1, High | after 7.2.6 | |
| CVE-2023-29180 A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 throu… | High7.5CVSS 3.1, High | after 7.2.3 | |
| CVE-2023-29181 A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6… | High8.8CVSS 3.1, High | after 7.2.4 | |
| CVE-2024-23113 Fortinet Multiple Products Format String Vulnerability | Critical9.8CVSS 3.1, CriticalKEV | after 7.2.8 | |
| CVE-2024-21762 Fortinet FortiOS Out-of-Bound Write Vulnerability | Critical9.8CVSS 3.1, CriticalKEVRansomware | after 7.2.8 | |
| CVE-2023-27997 Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | Critical9.8CVSS 3.1, CriticalKEVRansomware | after 7.2.3 | |
| CVE-2022-42475 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability | Critical9.8CVSS 3.1, CriticalKEVRansomware | after 7.2.1 |
CERT-FR advisories and alerts
Documents of the French national CERT referencing these CVEs, newest first.
- Advisory (AVI)CERTFR-2026-AVI-1015Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2026
- Advisory (AVI)CERTFR-2026-AVI-0097Vulnérabilité dans les produits FortinetPublished 28 Jan 2026
- Advisory (AVI)CERTFR-2025-AVI-1084Multiples vulnérabilités dans les produits FortinetPublished 10 Dec 2025
- Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
- Advisory (AVI)CERTFR-2025-AVI-0679Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2025
- Advisory (AVI)CERTFR-2025-AVI-0575Multiples vulnérabilités dans les produits FortinetPublished 9 Jul 2025
- Advisory (AVI)CERTFR-2025-AVI-0293Multiples vulnérabilités dans les produits FortinetPublished 9 Apr 2025
- Advisory (AVI)CERTFR-2025-AVI-0197Multiples vulnérabilités dans les produits FortinetPublished 12 Mar 2025
- Advisory (AVI)CERTFR-2025-AVI-0031Multiples vulnérabilités dans les produits FortinetPublished 15 Jan 2025
- Alert (ALE)CERTFR-2025-ALE-002[MàJ] Vulnérabilité dans les produits FortinetPublished 14 Jan 2025 · updated 7 May 2025 · closed 7 May 2025
- Advisory (AVI)CERTFR-2025-AVI-0030Multiples vulnérabilités dans les produits FortinetPublished 14 Jan 2025 · updated 12 Feb 2025
- Advisory (AVI)CERTFR-2024-AVI-0979Multiples vulnérabilités dans les produits FortinetPublished 13 Nov 2024
How Patcharo reads this
Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.