> ## Content Index
> Fetch the complete content index at: https://blog.elvatis.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# 🛡️ Fortinet Monthly Recap | December 2025
- URL: https://blog.elvatis.com/fortinet-monthly-recap-december-2025/
- Published: 2026-01-07T08:29:56.000Z
- Updated: 2026-08-31T09:53:30.000Z
- Description: Monthly Overview December 2025.
- Author: E. Kohler
- Tags: Fortinet, Monthly Recap, security, Cybersecurity, Vulnerability Management, December

## 📦 Firmware Updates

| Product                   | Version | Type    | Documentation                                                                                                                                                                                       |
| ------------------------- | ------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **FORTIADC**              | 8.0.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortiadc/8.0.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadc/8.0.2/administration-guide)                           |
| **FORTIADC**              | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiadc/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadc/7.6.5/administration-guide)                           |
| **FORTIAIOPS**            | 3.2.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortiaiops/3.2.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiaiops/3.2.0/administration-guide)                       |
| **FORTIANALYZER**         | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.6.5/administration-guide)                 |
| **FORTIAP-U**             | 7.0.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiap-u/7.0.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiap-u/7.0.6/administration-guide)                         |
| **FORTIAUTHENTICATOR**    | 6.6.8   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiauthenticator/6.6.8/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiauthenticator/6.6.8/administration-guide)       |
| **FORTICAMERA**           | 2.2.2   | Feature | [Release Notes](https://docs.fortinet.com/document/forticamera/2.2.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticamera/2.2.2/administration-guide)                     |
| **FORTICLIENT**           | 7.4.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlient/7.4.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlient/7.4.5/administration-guide)                     |
| **FORTICLIENTEMS**        | 7.4.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientems/7.4.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientems/7.4.5/administration-guide)               |
| **FORTICLIENTLINUX**      | 7.4.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientlinux/7.4.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientlinux/7.4.5/administration-guide)           |
| **FORTICLIENTMAC**        | 7.4.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientmac/7.4.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientmac/7.4.5/administration-guide)               |
| **FORTICONVERTER**        | 7.4.0   | Major   | [Release Notes](https://docs.fortinet.com/document/forticonverter/7.4.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticonverter/7.4.0/administration-guide)               |
| **FORTIDATA**             | 7.6.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortidata/7.6.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortidata/7.6.2/administration-guide)                         |
| **FORTIFONEANDROID**      | 7.2.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortifoneandroid/7.2.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortifoneandroid/7.2.0/administration-guide)           |
| **FORTIGUEST**            | 2.4.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortiguest/2.4.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiguest/2.4.2/administration-guide)                       |
| **FORTIMAIL**             | 7.4.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimail/7.4.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimail/7.4.6/administration-guide)                         |
| **FORTIMAIL**             | 7.2.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimail/7.2.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimail/7.2.9/administration-guide)                         |
| **FORTIMANAGER**          | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.6.5/administration-guide)                   |
| **FORTIMONITORONSIGHT**   | 7.2.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimonitoronsight/7.2.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimonitoronsight/7.2.9/administration-guide)     |
| **FORTINAC-F**            | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortinac-f/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortinac-f/7.6.5/administration-guide)                       |
| **FORTINACAGENT**         | 7.6.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortinacagent/7.6.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortinacagent/7.6.3/administration-guide)                 |
| **FORTIOS**               | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.6.5/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.6.5/administration-guide)                 |
| **FORTIPAM**              | 1.8.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortipam/1.8.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortipam/1.8.0/administration-guide)                           |
| **FORTIPORTAL**           | 7.4.8   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiportal/7.4.8/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiportal/7.4.8/administration-guide)                     |
| **FORTIRECORDER**         | 7.2.7   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortirecorder/7.2.7/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortirecorder/7.2.7/administration-guide)                 |
| **FORTISIEM**             | 7.5.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortisiem/7.5.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisiem/7.5.0/administration-guide)                         |
| **FORTISIEMWINDOWSAGENT** | 7.4.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortisiemwindowsagent/7.4.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisiemwindowsagent/7.4.2/administration-guide) |
| **FORTISOAR**             | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisoar/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisoar/7.6.5/administration-guide)                         |
| **FORTISWITCH**           | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitch/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitch/7.6.6/administration-guide)                     |
| **FORTISWITCH**           | 7.6.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitch/7.6.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitch/7.6.5/administration-guide)                     |
| **FORTISWITCHMANAGER**    | 7.0.7   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitchmanager/7.0.7/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchmanager/7.0.7/administration-guide)       |
| **FORTIVOICE**            | 7.4.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortivoice/7.4.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortivoice/7.4.0/administration-guide)                       |
| **FORTIVOICEUCDESKTOP**   | 7.0.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortivoiceucdesktop/7.0.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortivoiceucdesktop/7.0.3/administration-guide)     |
| **FORTIWEB**              | 8.0.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiweb/8.0.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiweb/8.0.3/administration-guide)                           |

## ⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in December:

| ID                                                                | Score | Description (Affected Versions)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ----------------------------------------------------------------- | ----- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2025-53679](https://nvd.nist.gov/vuln/detail/CVE-2025-53679) | 7.2   | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability \[CWE-78\] in Fortinet **FortiSandbox** 5.0.0 through 5.0.2,before 4.4.7 GUI allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.                                                                                                                                                                                                                                                                               |
| [CVE-2025-53949](https://nvd.nist.gov/vuln/detail/CVE-2025-53949) | 7.2   | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability \[CWE-78\] vulnerability in Fortinet **FortiSandbox** 5.0.0 through 5.0.2,**FortiSandbox** 4.4.0 through 4.4.7,**FortiSandbox** 4.2 all versions,**FortiSandbox** 4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests.                                                                                                                                                                     |
| [CVE-2025-59718](https://nvd.nist.gov/vuln/detail/CVE-2025-59718) | 9.8   | A improper verification of cryptographic signature vulnerability in Fortinet **FortiOS** 7.6.0 through 7.6.3,**FortiOS** 7.4.0 through 7.4.8,**FortiOS** 7.2.0 through 7.2.11,**FortiOS** 7.0.0 through 7.0.17,**FortiProxy** 7.6.0 through 7.6.3,**FortiProxy** 7.4.0 through 7.4.10,**FortiProxy** 7.2.0 through 7.2.14,**FortiProxy** 7.0.0 through 7.0.21,**FortiSwitchManager** 7.2.0 through 7.2.6,**FortiSwitchManager** 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the **FortiCloud** SSO login authentication via a crafted SAML response message.       |
| [CVE-2025-59719](https://nvd.nist.gov/vuln/detail/CVE-2025-59719) | 9.8   | An improper verification of cryptographic signature vulnerability in Fortinet **FortiWeb** 8.0.0,**FortiWeb** 7.6.0 through 7.6.4,**FortiWeb** 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the **FortiCloud** SSO login authentication via a crafted SAML response message.                                                                                                                                                                                                                                                                                     |
| [CVE-2025-59808](https://nvd.nist.gov/vuln/detail/CVE-2025-59808) | 6.8   | An unverified password change vulnerability \[CWE-620\] vulnerability in Fortinet **FortiSOAR** PaaS 7.6.0 through 7.6.2,**FortiSOAR** PaaS 7.5.0 through 7.5.1,**FortiSOAR** PaaS 7.4 all versions,**FortiSOAR** PaaS 7.3 all versions,**FortiSOAR** on-premise 7.6.0 through 7.6.2,**FortiSOAR** on-premise 7.5.0 through 7.5.1,**FortiSOAR** on-premise 7.4 all versions,**FortiSOAR** on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password |
| [CVE-2025-59810](https://nvd.nist.gov/vuln/detail/CVE-2025-59810) | 6.5   | An improper access control vulnerability in Fortinet **FortiSOAR** PaaS 7.6.0 through 7.6.2,**FortiSOAR** PaaS 7.5.0 through 7.5.1,**FortiSOAR** PaaS 7.4 all versions,**FortiSOAR** PaaS 7.3 all versions,**FortiSOAR** on-premise 7.6.0 through 7.6.2,**FortiSOAR** on-premise 7.5.0 through 7.5.1,**FortiSOAR** on-premise 7.4 all versions,**FortiSOAR** on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests                                                                                                             |
| [CVE-2025-60024](https://nvd.nist.gov/vuln/detail/CVE-2025-60024) | 8.8   | Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities \[CWE-22\] vulnerability in Fortinet **FortiVoice** 7.2.0 through 7.2.2,**FortiVoice** 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands                                                                                                                                                                                                                                                      |
| [CVE-2025-64153](https://nvd.nist.gov/vuln/detail/CVE-2025-64153) | 7.2   | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet **FortiExtender** 7.6.0 through 7.6.3,**FortiExtender** 7.4.0 through 7.4.7,**FortiExtender** 7.2 all versions,**FortiExtender** 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.                                                                                                                                                                                                                    |
| [CVE-2025-64156](https://nvd.nist.gov/vuln/detail/CVE-2025-64156) | 7.2   | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet **FortiVoice** 7.2.0 through 7.2.2,**FortiVoice** 7.0.0 through 7.0.7,**FortiVoice** 6.4 all versions,**FortiVoice** 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests                                                                                                                                                                                                                    |
| [CVE-2025-64447](https://nvd.nist.gov/vuln/detail/CVE-2025-64447) | 8.1   | A reliance on cookies without validation and integrity checking vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.1,**FortiWeb** 7.6.0 through 7.6.5,**FortiWeb** 7.4.0 through 7.4.10,**FortiWeb** 7.2.0 through 7.2.11,**FortiWeb** 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies,requiring prior knowledge of the **FortiWeb** serial number.                                                                                                                 |