CVE-2025-48839: Fortinet FortiADC

Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

Affected products

  • Fortinet FortiADC: from 6.2.0, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.3 (fixed in 7.6.3); version 8.0.0 only

Published 2025-11-18. Last modified 2026-06-17.