PoC Archive PoC Archive

tag

Fortinet

FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446) KEV EPSS 92%
CVE-2025-64446 network Unverified
CVE-2025-64446networkCRITICAL 9.8Unverified2026-07-06FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718) KEV EPSS 69%
CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719) network Patched
CVE-2025-59718networkCRITICAL 9.8Patched2026-07-06FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CVE-2026-39808networkCRITICAL 9.8Unverified2026-07-05Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CVE-2026-25089networkCRITICAL 9.8Patched2026-07-05FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 web Patched
CVE-2026-44277webCRITICALPatched2026-07-05Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616) KEV EPSS 91%
CVE-2026-35616 network Patched
CVE-2026-35616networkCRITICAL 9.1Patched2026-07-03