tag
Loopback-Spoofing
CVE-2022-40684
network
CRITICAL 9.8
KEV
Ransomware
EPSS 100%
CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)
CVE-2022-40684 is an authentication-bypass vulnerability in the web management interface of FortiOS, FortiProxy, and FortiSwitchManager that allows an unauthenticated remote attacker to access the administrative REST API. The affected firmware fails to…
Unverified
2026-07-31