CVE-2023-36555: Fortinet FortiOS

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.

Affected products

  • Fortinet FortiOS: from 7.2.0, up to and including 7.2.4

Published 2023-10-10. Last modified 2026-06-17.