📦 Fortiproxy

by Fortinet

🔍 What is Fortiproxy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24858

CRITICAL CVSS 9.8 Jan 27, 2026

This authentication bypass vulnerability allows attackers with a FortiCloud account and registered device to log into other organizations' Fortinet devices when FortiCloud SSO authentication is enable...

CVE-2025-22252

CRITICAL CVSS 9.8 May 28, 2025

This vulnerability allows attackers who know an existing admin account name to bypass authentication and gain full administrative access to affected Fortinet devices. It affects FortiProxy, FortiSwitc...

CVE-2023-25610

CRITICAL CVSS 9.8 Mar 24, 2025

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices via crafted requests to the administrative interface. It affects ...

CVE-2024-55591

CRITICAL CVSS 9.8 Jan 14, 2025

This vulnerability allows remote attackers to bypass authentication and gain super-admin privileges on affected Fortinet devices by sending crafted requests to the Node.js websocket module. It affects...

CVE-2024-48886

CRITICAL CVSS 9.0 Jan 14, 2025

This vulnerability allows attackers to bypass weak authentication mechanisms in multiple Fortinet products via brute-force attacks, potentially leading to unauthorized command execution. Affected syst...

CVE-2023-42789

CRITICAL CVSS 9.8 Mar 12, 2024

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices via specially crafted HTTP requests. It affects FortiOS and FortiProxy across mul...

CVE-2024-23113

CRITICAL CVSS 9.8 Feb 15, 2024

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets that exploit a format string vulnerability. ...

CVE-2024-21762

CRITICAL CVSS 9.8 Feb 9, 2024

This critical vulnerability allows remote attackers to execute arbitrary code or commands on affected Fortinet devices via specially crafted requests. An out-of-bounds write in FortiOS and FortiProxy ...

CVE-2023-33308

CRITICAL CVSS 9.8 Jul 26, 2023

A critical stack-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy allows remote unauthenticated attackers to execute arbitrary code via specially crafted packets. This affects sy...

CVE-2023-27997

CRITICAL CVSS 9.8 Jun 13, 2023

A heap-based buffer overflow vulnerability in Fortinet's SSL-VPN implementation allows remote attackers to execute arbitrary code via crafted requests. This affects FortiOS versions 7.2.4 and below, 7...

CVE-2022-41331

CRITICAL CVSS 9.8 Apr 11, 2023

CVE-2022-41331 allows remote unauthenticated attackers to access Redis and MongoDB databases in FortiPresence infrastructure servers. This affects organizations running FortiPresence servers before ve...

CVE-2025-57740

HIGH CVSS 7.5 Oct 14, 2025

A heap-based buffer overflow vulnerability in Fortinet's FortiOS, FortiPAM, and FortiProxy allows authenticated users to execute arbitrary code via crafted RDP bookmark connection requests. This affec...

CVE-2025-25253

HIGH CVSS 7.5 Oct 14, 2025

This vulnerability allows man-in-the-middle attackers to intercept and tamper with connections to Fortinet's ZTNA proxy by exploiting improper certificate validation. It affects FortiProxy and FortiOS...

CVE-2024-26009

HIGH CVSS 8.1 Aug 12, 2025

This CVE describes an authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiPAM products that allows unauthenticated attackers to take control of managed devices. Attackers can...

CVE-2023-37930

HIGH CVSS 7.5 Apr 8, 2025

This CVE describes memory corruption vulnerabilities in Fortinet VPN products that could allow authenticated VPN users to execute arbitrary code or commands. The vulnerabilities stem from uninitialize...

CVE-2024-26006

HIGH CVSS 7.5 Mar 14, 2025

This vulnerability allows remote unauthenticated attackers to perform cross-site scripting (XSS) attacks through the SSL VPN web interface in affected Fortinet products. Attackers can inject malicious...

CVE-2024-45324

HIGH CVSS 7.2 Mar 11, 2025

A format string vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code via crafted HTTP/HTTPS requests. This affects FortiOS, FortiProxy, FortiPAM, FortiSRA,...

CVE-2025-24472

HIGH CVSS 8.1 Feb 11, 2025

This authentication bypass vulnerability in FortiOS and FortiProxy allows remote unauthenticated attackers to gain super-admin privileges on downstream devices when Security Fabric is enabled. Attacke...

CVE-2023-41677

HIGH CVSS 7.5 Apr 9, 2024

This vulnerability involves insufficiently protected credentials in Fortinet FortiProxy and FortiOS, allowing attackers to execute unauthorized code or commands via social engineering attacks. Affecte...

CVE-2024-23112

HIGH CVSS 8.0 Mar 12, 2024

This CVE describes an authorization bypass vulnerability in FortiOS and FortiProxy SSL-VPN that allows authenticated attackers to access other users' bookmarks through URL manipulation. Attackers can ...

CVE-2023-29180

HIGH CVSS 7.5 Feb 22, 2024

A null pointer dereference vulnerability in Fortinet FortiOS and FortiProxy allows attackers to cause denial of service via specially crafted HTTP requests. This affects multiple versions of both prod...

CVE-2023-44250

HIGH CVSS 8.8 Jan 10, 2024

This vulnerability allows authenticated attackers in Fortinet FortiOS and FortiProxy HA clusters to perform elevated actions through crafted HTTP/HTTPS requests. It affects organizations running vulne...

CVE-2023-29183

HIGH CVSS 8.0 Sep 13, 2023

This cross-site scripting (XSS) vulnerability in Fortinet's FortiProxy and FortiOS web management interfaces allows authenticated attackers to inject and execute malicious JavaScript code via crafted ...

CVE-2022-41327

HIGH CVSS 7.8 Jun 13, 2023

This vulnerability allows authenticated attackers with readonly superadmin privileges in Fortinet FortiOS and FortiProxy to intercept cleartext traffic and obtain other administrators' session cookies...

CVE-2023-22640

HIGH CVSS 7.5 May 3, 2023

This CVE describes an out-of-bounds write vulnerability in multiple Fortinet products that allows authenticated attackers to execute arbitrary code or commands via crafted requests. Affected systems i...

CVE-2022-41330

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows unauthenticated attackers to execute cross-site scripting (XSS) attacks against Fortinet FortiOS and FortiProxy devices via crafted HTTP GET requests. Attackers can inject ma...

CVE-2022-41335

HIGH CVSS 8.8 Feb 16, 2023

This CVE-2022-41335 is a relative path traversal vulnerability in Fortinet products that allows authenticated attackers to read and write arbitrary files on the underlying Linux system via crafted HTT...

CVE-2021-41024

HIGH CVSS 7.5 Dec 8, 2021

This vulnerability allows unauthenticated attackers to perform path traversal attacks on FortiOS and FortiProxy login pages, potentially exposing sensitive server information. Attackers can inject pat...

CVE-2021-26110

HIGH CVSS 7.8 Dec 8, 2021

This vulnerability allows authenticated low-privileged attackers to escalate their privileges to super_admin on affected Fortinet devices. Attackers can exploit improper access control in the autod da...

CVE-2021-22128

HIGH CVSS 7.1 Mar 4, 2021

This vulnerability allows authenticated remote attackers to bypass access controls in FortiProxy SSL VPN portal, potentially accessing internal services like the ZebOS Shell. Affected systems include ...

CVE-2024-47570

MEDIUM CVSS 6.6 Dec 9, 2025

This vulnerability allows read-only administrators to retrieve API tokens of other administrators by examining REST API logs when REST API logging is enabled. This affects Fortinet's FortiOS, FortiPro...

CVE-2025-54822

MEDIUM CVSS 4.3 Oct 14, 2025

An authenticated attacker can access static files from other VDOMs (Virtual Domains) in affected Fortinet products by sending specially crafted HTTP/HTTPS requests. This improper authorization vulnera...

CVE-2025-31366

MEDIUM CVSS 4.7 Oct 14, 2025

This vulnerability allows unauthenticated attackers to perform reflected cross-site scripting (XSS) attacks against Fortinet FortiOS, FortiProxy, and FortiSASE products via crafted HTTP requests. Atta...

CVE-2024-26008

MEDIUM CVSS 5.3 Oct 14, 2025

This vulnerability allows an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests, causing denial of service. Affected systems include FortiOS, Forti...

CVE-2023-46718

MEDIUM CVSS 6.7 Oct 14, 2025

This CVE describes a stack-based buffer overflow vulnerability in Fortinet FortiOS that allows attackers to execute arbitrary code or commands via specially crafted CLI commands. The vulnerability aff...

CVE-2025-22862

MEDIUM CVSS 6.7 Oct 2, 2025

This CVE describes an authentication bypass vulnerability in FortiOS and FortiProxy that allows authenticated attackers to elevate privileges via malicious Webhook actions in the Automation Stitch com...

CVE-2025-25248

MEDIUM CVSS 5.3 Aug 12, 2025

An integer overflow vulnerability in Fortinet SSL-VPN RDP/VNC bookmarks allows authenticated users to craft requests that may crash the SSL-VPN service, causing denial of service. This affects FortiOS...

CVE-2023-45584

MEDIUM CVSS 6.6 Aug 12, 2025

A double free vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code or commands via crafted HTTP/HTTPS requests. This affects FortiOS, FortiPAM, and FortiPr...

CVE-2024-55599

MEDIUM CVSS 5.3 Jul 8, 2025

This vulnerability allows remote unauthenticated attackers to bypass DNS filtering protections on Fortinet devices when Apple devices are used. It affects FortiOS and FortiProxy across multiple versio...

CVE-2025-22254

MEDIUM CVSS 6.6 Jun 10, 2025

This CVE describes an improper privilege management vulnerability in multiple Fortinet products where authenticated users with read-only admin permissions can escalate to super-admin privileges via cr...

CVE-2019-15706

MEDIUM CVSS 4.1 Mar 17, 2025

This vulnerability allows authenticated remote attackers to inject malicious scripts into the SSL VPN portal of affected Fortinet devices. When other users access the compromised portal pages, the scr...

CVE-2022-23439

MEDIUM CVSS 4.7 Jan 22, 2025

This vulnerability allows attackers to poison web caches by sending crafted HTTP requests with malicious Host headers to Fortinet devices. Attackers can redirect users to arbitrary malicious servers, ...

CVE-2024-33510

MEDIUM CVSS 4.3 Nov 12, 2024

This CVE describes an injection vulnerability in Fortinet's SSL-VPN web user interface that could allow remote unauthenticated attackers to perform phishing attempts. The vulnerability affects FortiOS...

CVE-2024-26011

MEDIUM CVSS 5.3 Nov 12, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets. It affects multiple Fortinet products inclu...

CVE-2023-45583

MEDIUM CVSS 6.7 May 14, 2024

This CVE describes a format string vulnerability in multiple Fortinet products that allows attackers to execute arbitrary code or commands. The vulnerability affects FortiProxy, FortiPAM, FortiOS, and...

CVE-2025-54821

LOW CVSS 1.9 Nov 18, 2025

This CVE describes an improper privilege management vulnerability in multiple Fortinet products that allows authenticated administrators to bypass trusted host policies via crafted CLI commands. The v...