PoC Archive PoC Archive

tag

FortiOS

  • CVE-2022-40684 network CRITICAL 9.8 KEV Ransomware EPSS 100%

    CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)

    CVE-2022-40684 is an authentication-bypass vulnerability in the web management interface of FortiOS, FortiProxy, and FortiSwitchManager that allows an unauthenticated remote attacker to access the administrative REST API. The affected firmware fails to…

    Unverified 2026-07-31
  • CVE-2025-59718 network CRITICAL 9.8 KEV EPSS 63%

    FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)

    CVE-2025-59718 is an improper verification of a cryptographic signature in Fortinet's FortiCloud SSO admin-login flow across FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb, allowing authentication bypass when admin-forticloud-sso-login is enabled on a…

    Patched 2026-07-06
  • CVE-2025-59718, CVE-2025-59719 network CRITICAL 9.8 KEV EPSS 63%

    Fortinet FortiCloud SSO Authentication Bypass

    CVE-2025-59718 and CVE-2025-59719 are closely related authentication-bypass vulnerabilities (CWE-347: Improper Verification of Cryptographic Signature) in Fortinet products that use the FortiCloud SSO login feature. Both were disclosed by Fortinet on 9…

    Unverified 2026-05-17
  • CVE-2024-21762 web CRITICAL 9.6 KEV Ransomware EPSS 84%

    Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)

    CVE-2024-21762 is a critical out-of-bounds write in FortiOS sslvpnd reachable through the SSL VPN web interface. A remote unauthenticated attacker can send crafted HTTP requests to corrupt memory and potentially achieve remote code execution. Public reporting…

    Patched 2026-05-16
  • CVE-2024-55591 web CRITICAL 9.6 KEV Ransomware EPSS 98%

    Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)

    CVE-2024-55591 is an authentication bypass in Fortinet management interfaces that can be abused over a crafted WebSocket workflow. The public PoC demonstrates racing WebSocket login-context traffic to gain effective super-admin CLI access without valid…

    Unverified 2026-05-16