Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Fortinet · AUTOMATIC DISCOVERY

FortiOS Product policy

FortiOS is tracked by BlackTree as an operating system or system software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

FortiOS is tracked by BlackTree as an operating system or system software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application and workload execution
  • Hardware, networking and storage management
  • Security updates and platform maintenance

Typical use

Used on endpoints, servers, appliances, virtual machines or cloud instances.

Deployment

Installed on physical or virtual systems, or delivered as an appliance or cloud image.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductFortiOS
ReleaseProduct policy
End of Support11 November 2028
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2025-25249Added 9 Sep 2026

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

Fortinet · Multiple ProductsRansomware use: Unknown

CISA entry
CVE-2025-68686Added 27 Jul 2026

Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Fortinet · FortiOSRansomware use: Unknown

CISA entry
CVE-2026-24858Added 27 Jan 2026

Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Fortinet · Multiple ProductsRansomware use: Unknown

CISA entry
CVE-2025-59718Added 16 Dec 2025

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

Fortinet · Multiple ProductsRansomware use: Unknown

CISA entry
CVE-2019-6693Added 25 Jun 2025

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

Fortinet · FortiOSRansomware use: Known

CISA entry
CVE-2025-24472Added 18 Mar 2025

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

Fortinet · FortiOS and FortiProxyRansomware use: Known

CISA entry

Showing the 6 most recently added of 20 product-family matches.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYPartial

FortiOS official lifecycle source

23228 views | As announced in Customer Support Bulletin CSB-260330-1, as of March 2026, the following firmware Product Life Cycle Dates have been extended by one year: | FortiOS v7.4 End of Engineering Support: 11 May 2026 -> 11 May 2027. | FortiOS v7.4 End of Support: 11 Nov 2027 -> 11 Nov 2028. | FortiOS v7.6 End of Engineering Support: 25 Jul 2027 -> 25 Jul 2028. | FortiOS v7.6 End of Support: 25 Jan 2029 -> 25 Jan 2030. | Up-to-date product Life Cycle information can be viewed at Life Cycle .

Official vendor lifecycle or product-change property. Extracted records require human review.

First collected 31 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source