PoC Archive PoC Archive

tag

Fortinet

  • CVE-2025-64446 network CRITICAL 9.8 KEV EPSS 92%

    FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)

    FortiWeb exposes an internal CGI handler (cgi-bin/fwbcgi) that is reachable through the authenticated cmdb REST API path by appending a relative path-traversal sequence (../) after a request to a nonexistent object (admin%3f). Because path handling for the…

    Unverified 2026-07-06
  • CVE-2025-59718 network CRITICAL 9.8 KEV EPSS 63%

    FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)

    CVE-2025-59718 is an improper verification of a cryptographic signature in Fortinet's FortiCloud SSO admin-login flow across FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb, allowing authentication bypass when admin-forticloud-sso-login is enabled on a…

    Patched 2026-07-06
  • CVE-2026-39808 network CRITICAL 9.8 KEV EPSS 91%

    FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)

    FortiSandbox versions 4.4.0 through 4.4.8 contain a critical OS command injection vulnerability in the tracer-behavior API endpoint (job-detail/tracer-behavior), reachable via the jid request parameter. Improper neutralization of special shell characters…

    Unverified 2026-07-05
  • CVE-2026-25089 network CRITICAL 9.8 KEV EPSS 74%

    Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)

    FortiSandbox's Web UI "start VNC" feature passes a caller-supplied virtual machine name into an OS command without proper neutralization of shell metacharacters, allowing an unauthenticated attacker to inject arbitrary commands executed on the underlying…

    Patched 2026-07-05
  • CVE-2026-44277 web CRITICAL

    FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)

    CVE-2026-44277 is described by the vendor/advisory as an unauthenticated remote code execution vulnerability in Fortinet FortiAuthenticator, caused by improper access control on specific API endpoints. The included script is a reconnaissance/detection tool…

    Patched 2026-07-05
  • CVE-2026-35616 network CRITICAL 9.1 KEV EPSS 89%

    Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)

    CVE-2026-35616 is a pre-authentication bypass in Fortinet FortiClient EMS's certificate-chain authentication handler (certchainauth.py), which trusts the X-SSL-CLIENT-VERIFY header directly without performing real cryptographic validation of the presented…

    Patched 2026-07-03