Product overview
FortiOS is tracked by BlackTree as an operating system or system software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Application and workload execution
- Hardware, networking and storage management
- Security updates and platform maintenance
Typical use
Used on endpoints, servers, appliances, virtual machines or cloud instances.
Deployment
Installed on physical or virtual systems, or delivered as an appliance or cloud image.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | FortiOS |
|---|
| Release | Product policy |
|---|
| End of Support | 11 November 2028 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 11 Sep 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Fortinet · Multiple ProductsRansomware use: Unknown
CISA entry ↗Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Fortinet · FortiOSRansomware use: Unknown
CISA entry ↗Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Fortinet · Multiple ProductsRansomware use: Unknown
CISA entry ↗Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
Fortinet · Multiple ProductsRansomware use: Unknown
CISA entry ↗Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
Fortinet · FortiOSRansomware use: Known
CISA entry ↗Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
Fortinet · FortiOS and FortiProxyRansomware use: Known
CISA entry ↗Showing the 6 most recently added of 20 product-family matches.
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYPartial
FortiOS official lifecycle source
23228 views | As announced in Customer Support Bulletin CSB-260330-1, as of March 2026, the following firmware Product Life Cycle Dates have been extended by one year: | FortiOS v7.4 End of Engineering Support: 11 May 2026 -> 11 May 2027. | FortiOS v7.4 End of Support: 11 Nov 2027 -> 11 Nov 2028. | FortiOS v7.6 End of Engineering Support: 25 Jul 2027 -> 25 Jul 2028. | FortiOS v7.6 End of Support: 25 Jan 2029 -> 25 Jan 2030. | Up-to-date product Life Cycle information can be viewed at Life Cycle .
Official vendor lifecycle or product-change property. Extracted records require human review.
First collected 31 Aug 2026 · Last collected 12 Sep 2026 · Review state accepted
Open official vendor source ↗