CVE-2026-22153: Fortinet FortiOS

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

Affected products

  • Fortinet FortiOS: from 7.6.0, before 7.6.5 (fixed in 7.6.5)

Published 2026-02-10. Last modified 2026-06-17.