Skip to content

Fortinet FortiProxy 7.6

Vulnerabilities, fixed releases, vendor recommendation and support status of the 7.6 branch, from official sources.

Patcharo matches 11 vulnerabilities against Fortinet FortiProxy 7.6: 2 critical, 2 known exploited (CISA KEV). Newest fixed release stated by the vendor on this branch: none stated. Last source modification: 8 Sept 2026.

Last verified by Patcharo: 30 Sept 2026 at 09:17 UTC

In brief

Matched CVEs
11
CISA KEV
2
Newest fix stated
none stated
Support
No statement in the catalog
Recommended maintenance build
No official recommendation
Recommended release
No official recommendation
CERT-FR
8 documents

Support status

From the vendor's published life-cycle policy; support is not a recommendation.

The life-cycle policy Patcharo reads states nothing about this branch.

Vendor recommendation

The vendor's own statement about what to run, with its date and source. Separate from vulnerabilities and from support status: being behind a recommendation is not a vulnerability, and a supported release is not necessarily the recommended one.

Fortinet publishes no recommended-release page Patcharo can read. The fixed releases on this site come from the security advisories only; nothing is inferred from version numbers.

Vulnerabilities affecting 7.6

Each record matched to this branch with the fixed release the source states, newest first.

CVESeverityFixed inPublished
CVE-2026-71407

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 m…

High8.1CVSS 3.1, Highafter 7.6.4
CVE-2026-24858

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Critical9.8CVSS 3.1, CriticalKEVafter 7.6.4
CVE-2025-59718

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Critical9.8CVSS 3.1, CriticalKEVafter 7.6.3
CVE-2024-50571

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0…

High7.2CVSS 3.1, HighNo fix stated
CVE-2025-22258

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1…

High7.2CVSS 3.1, Highafter 7.6.1
CVE-2025-25253

An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 …

High7.5CVSS 3.1, Highafter 7.6.1
CVE-2025-57740

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and b…

High8.8CVSS 3.1, Highafter 7.6.2
CVE-2024-52965

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7…

High7.2CVSS 3.1, Highafter 7.6.1
CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.…

High7.2CVSS 3.1, Highafter 7.6.1
CVE-2025-22252

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwit…

High7.2CVSS 3.1, Highafter 7.6.1
CVE-2024-45324

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, …

High7.2CVSS 3.1, HighNo fix stated

CERT-FR advisories and alerts

Documents of the French national CERT referencing these CVEs, newest first.

  • Advisory (AVI)CERTFR-2026-AVI-1015Multiples vulnérabilités dans les produits FortinetPublished 13 Aug 2026
  • Advisory (AVI)CERTFR-2026-AVI-0097Vulnérabilité dans les produits FortinetPublished 28 Jan 2026
  • Advisory (AVI)CERTFR-2025-AVI-1084Multiples vulnérabilités dans les produits FortinetPublished 10 Dec 2025
  • Advisory (AVI)CERTFR-2025-AVI-0871Multiples vulnérabilités dans les produits FortinetPublished 15 Oct 2025
  • Advisory (AVI)CERTFR-2025-AVI-0575Multiples vulnérabilités dans les produits FortinetPublished 9 Jul 2025
  • Advisory (AVI)CERTFR-2025-AVI-0496Multiples vulnérabilités dans les produits FortinetPublished 11 Jun 2025
  • Advisory (AVI)CERTFR-2025-AVI-0399Multiples vulnérabilités dans les produits FortinetPublished 13 May 2025
  • Advisory (AVI)CERTFR-2025-AVI-0197Multiples vulnérabilités dans les produits FortinetPublished 12 Mar 2025

How Patcharo reads this

Affected and fixed releases come from the vendor's structured statements, matched by exact version and patch level. The recommendation is the vendor's own statement; the support status comes from its life-cycle policy. Unknown never becomes Not affected.

Read the methodology

Other FortiProxy branches

All FortiProxy vulnerabilities and branches

Official sources