CVE-2025-68482: Fortinet Fortianalyzer
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
Affected products
- Fortinet Fortianalyzer: from 6.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.5 (fixed in 7.6.5)
- Fortinet FortiManager: from 6.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.5 (fixed in 7.6.5)
Published 2026-03-10. Last modified 2026-06-17.