CVE-2024-26009: Fortinet FortiOS
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through 7.2.8, FortiProxy 7.0.0 through 7.0.15, FortiSwitchManager 7.2.0 through 7.2.3, FortiSwitchManager 7.0.0 through 7.0.3 allows an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number.
Affected products
- Fortinet FortiOS: from 6.0.0, before 6.2.17 (fixed in 6.2.17); from 6.4.0, before 6.4.16 (fixed in 6.4.16)
- Fortinet Fortipam: from 1.0.0, up to and including 1.2.0
- Fortinet FortiProxy: from 7.0.0, before 7.0.16 (fixed in 7.0.16); from 7.2.0, before 7.2.9 (fixed in 7.2.9); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet Fortiswitchmanager: from 7.0.0, before 7.0.4 (fixed in 7.0.4); from 7.2.0, before 7.2.4 (fixed in 7.2.4)
Published 2025-08-12. Last modified 2026-06-17.