🛡️ Fortinet Monthly Recap | April 2026

Monthly Overview April 2026.

🛡️ Fortinet Monthly Recap | April 2026

📦 Firmware Updates

ProductVersionTypeDocumentation
COLLECTORWINDOWS6.1.1PatchRelease Notes | Admin Guide
FORTIADC8.0.3PatchRelease Notes | Admin Guide
FORTIANALYZER8.0.0MajorRelease Notes | Admin Guide
FORTIAP-W27.4.6PatchRelease Notes | Admin Guide
FORTIAUTHENTICATOR8.0.3PatchRelease Notes | Admin Guide
FORTICENTRAL7.4.0MajorRelease Notes | Admin Guide
FORTICLIENT7.4.7PatchRelease Notes | Admin Guide
FORTICLIENTEMS7.4.7PatchRelease Notes | Admin Guide
FORTICLIENTLINUX7.4.7PatchRelease Notes | Admin Guide
FORTICLIENTMAC7.4.7PatchRelease Notes | Admin Guide
FORTIDDOS-F8.0.0MajorRelease Notes | Admin Guide
FORTIGUEST2.4.3PatchRelease Notes | Admin Guide
FORTIMANAGER8.0.0MajorRelease Notes | Admin Guide
FORTINACAGENT7.6.4FeatureRelease Notes | Admin Guide
FORTIOS8.0.0MajorRelease Notes | Admin Guide
FORTIPORTAL7.4.10PatchRelease Notes | Admin Guide
FORTIRECORDER7.2.10PatchRelease Notes | Admin Guide
FORTISOAR7.6.6PatchRelease Notes | Admin Guide
FORTISWITCHAXCHASSIS1.1.0MajorRelease Notes | Admin Guide
FORTISWITCHAXFIXED1.0.3PatchRelease Notes | Admin Guide
FORTISWITCHNMS1.13.3PatchRelease Notes | Admin Guide
FORTIVOICE7.2.4FeatureRelease Notes | Admin Guide
FORTIVOICEUCDESKTOP7.0.5PatchRelease Notes | Admin Guide
FORTIWEB8.0.5PatchRelease Notes | Admin Guide

⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in April:

IDScoreDescription (Affected Versions)
CVE-2026-356169.8A improper access control vulnerability in Fortinet

FortiClientEMS
7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CVE-2026-398089.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

FortiSandbox
4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via
CVE-2026-398139.8A path traversal: '../filedir' vulnerability in Fortinet

FortiSandbox
5.0.0 through 5.0.5,


FortiSandbox
4.4.0 through 4.4.8 may allow attacker to escalation of privilege via
CVE-2026-398158.8A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet

FortiDDoS
-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests
CVE-2026-228288.1A heap-based buffer overflow vulnerability in Fortinet

FortiAnalyzer Cloud
7.6.2 through 7.6.4,


FortiManager Cloud
7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation
CVE-2026-237087.5A improper authentication vulnerability in Fortinet

FortiSOAR
PaaS 7.6.0 through 7.6.3,


FortiSOAR
PaaS 7.5.0 through 7.5.2,


FortiSOAR
on-premise 7.6.0 through 7.6.3,


FortiSOAR
on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration,
which raises the attack complexity.
CVE-2025-618487.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.4,


FortiAnalyzer
7.4.0 through 7.4.8,


FortiAnalyzer
7.2 all versions,


FortiAnalyzer
7.0 all versions,


FortiAnalyzer Cloud
7.6.0 through 7.6.4,


FortiAnalyzer Cloud
7.4.0 through 7.4.8,


FortiAnalyzer Cloud
7.2 all versions,


FortiAnalyzer Cloud
7.0 all versions,


FortiManager
7.6.0 through 7.6.4,


FortiManager
7.4.0 through 7.4.8,


FortiManager
7.2 all versions,


FortiManager
7.0 all versions,


FortiManager Cloud
7.6.0 through 7.6.4,


FortiManager Cloud
7.4.0 through 7.4.8,


FortiManager Cloud
7.2 all versions,


FortiManager Cloud
7.0 all versions may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API
CVE-2026-406887.2An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.3,


FortiWeb
7.6.0 through 7.6.6,


FortiWeb
7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.
CVE-2026-256916.7A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet

FortiSandbox
5.0.0 through 5.0.5,


FortiSandbox
4.4.0 through 4.4.8,


FortiSandbox
4.2 all versions,


FortiSandbox Cloud
5.0.4,


FortiSandbox
PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.
CVE-2026-398096.7A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet

FortiClientEMS
7.4.0 through 7.4.5,


FortiClientEMS
7.2.0 through 7.2.12,


FortiClientEMS
7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
CVE-2026-398146.7A relative path traversal vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.2,


FortiWeb
7.6.0 through 7.6.6,


FortiWeb
7.4.1 through 7.4.12,


FortiWeb
7.2.7 through 7.2.12,


FortiWeb
7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via
CVE-2025-538476.5A missing authentication for critical function vulnerability in Fortinet

FortiOS
7.6.0 through 7.6.3,


FortiOS
7.4.0 through 7.4.8,


FortiOS
7.2.0 through 7.2.11,


FortiOS
7.0.0 through 7.0.17,


FortiOS
6.4 all versions,


FortiOS
6.2.9 through 6.2.17

allows attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2026-221556.5A cleartext transmission of sensitive information vulnerability in Fortinet

FortiSOAR
PaaS 7.6.0 through 7.6.3,


FortiSOAR
PaaS 7.5.0 through 7.5.2,


FortiSOAR
PaaS 7.4 all versions,


FortiSOAR
PaaS 7.3 all versions,


FortiSOAR
on-premise 7.6.0 through 7.6.2,


FortiSOAR
on-premise 7.5.0 through 7.5.1,


FortiSOAR
on-premise 7.4 all versions,


FortiSOAR
on-premise 7.3 all versions may allow attacker to information disclosure via
CVE-2026-225736.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet

FortiSOAR
PaaS 7.6.0 through 7.6.3,


FortiSOAR
PaaS 7.5 all versions,


FortiSOAR
PaaS 7.4 all versions,


FortiSOAR
PaaS 7.3 all versions,


FortiSOAR
on-premise 7.6.0 through 7.6.3,


FortiSOAR
on-premise 7.5 all versions,


FortiSOAR
on-premise 7.4 all versions,


FortiSOAR
on-premise 7.3 all versions may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions.