CVE-2026-22572: Fortinet Fortianalyzer
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
Affected products
- Fortinet Fortianalyzer: from 7.2.2, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
- Fortinet FortiManager: from 7.2.2, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
- Fortinet FortiManager Cloud: from 7.2.2, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
Published 2026-03-10. Last modified 2026-06-17.