CVE-2025-53744: Fortinet FortiOS

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.

Affected products

  • Fortinet FortiOS: from 6.4.0, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.3 (fixed in 7.6.3)

Published 2025-08-12. Last modified 2026-06-17.