CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-05-14. EPSS: 30.7% chance of exploitation in the next 30 days.
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Affected products
- Fortinet Forticamera Firmware: from 2.0.0, up to and including 2.1.3; from 1.1.0, up to and including 1.1.5
- Fortinet FortiMail: from 7.0.0, before 7.0.9 (fixed in 7.0.9); from 7.2.0, before 7.2.8 (fixed in 7.2.8); from 7.4.0, before 7.4.5 (fixed in 7.4.5); from 7.6.0, before 7.6.3 (fixed in 7.6.3)
- Fortinet Fortindr: from 7.0.0, before 7.0.7 (fixed in 7.0.7); from 7.2.0, before 7.2.5 (fixed in 7.2.5); from 7.4.0, before 7.4.8 (fixed in 7.4.8); version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; …
- Fortinet Fortirecorder: from 6.4.0, before 6.4.6 (fixed in 6.4.6); from 7.0.0, before 7.0.6 (fixed in 7.0.6); from 7.2.0, before 7.2.4 (fixed in 7.2.4)
- Fortinet Fortivoice: from 6.4.0, before 6.4.11 (fixed in 6.4.11); from 7.0.0, before 7.0.7 (fixed in 7.0.7); version 7.2.0 only
Published 2025-05-13. Last modified 2026-06-17.