🛡️ Fortinet Monthly Recap | Dezember 2025

Monatsübersicht Dezember 2025.

📦 Firmware Updates

ProduktVersionTypDokumentation
FORTIDATA7.6.2FeatureRelease Notes | Admin Guide
FORTIRECORDER7.2.7PatchRelease Notes | Admin Guide
FORTIPORTAL7.4.8PatchRelease Notes | Admin Guide
FORTIADC7.6.5PatchRelease Notes | Admin Guide
FORTISIEM7.5.0MajorRelease Notes | Admin Guide
FORTISIEMWINDOWSAGENT7.4.2FeatureRelease Notes | Admin Guide
FORTISOAR7.6.5PatchRelease Notes | Admin Guide
FORTIVOICEUCDESKTOP7.0.3PatchRelease Notes | Admin Guide
FORTISWITCH7.6.6PatchRelease Notes | Admin Guide
FORTIVOICE7.4.0MajorRelease Notes | Admin Guide
FORTINACAGENT7.6.3PatchRelease Notes | Admin Guide
FORTIANALYZER7.6.5PatchRelease Notes | Admin Guide
FORTIMANAGER7.6.5PatchRelease Notes | Admin Guide
FORTIWEB8.0.3PatchRelease Notes | Admin Guide
FORTIADC8.0.2FeatureRelease Notes | Admin Guide
FORTIAIOPS3.2.0MajorRelease Notes | Admin Guide
FORTIGUEST2.4.2FeatureRelease Notes | Admin Guide
FORTICLIENTEMS7.4.5PatchRelease Notes | Admin Guide
FORTICLIENTLINUX7.4.5PatchRelease Notes | Admin Guide
FORTICLIENTMAC7.4.5PatchRelease Notes | Admin Guide
FORTICLIENT7.4.5PatchRelease Notes | Admin Guide
FORTIMONITORONSIGHT7.2.9PatchRelease Notes | Admin Guide
FORTIMAIL7.4.6PatchRelease Notes | Admin Guide
FORTIAUTHENTICATOR6.6.8PatchRelease Notes | Admin Guide
FORTIOS7.6.5PatchRelease Notes | Admin Guide
FORTIAP-U7.0.6PatchRelease Notes | Admin Guide
FORTIMAIL7.2.9PatchRelease Notes | Admin Guide
FORTICAMERA2.2.2FeatureRelease Notes | Admin Guide
FORTICONVERTER7.4.0MajorRelease Notes | Admin Guide
FORTIFONEANDROID7.2.0MajorRelease Notes | Admin Guide
FORTISWITCH7.6.5PatchRelease Notes | Admin Guide
FORTIPAM1.8.0MajorRelease Notes | Admin Guide
FORTINAC-F7.6.5PatchRelease Notes | Admin Guide
FORTISWITCHMANAGER7.0.7PatchRelease Notes | Admin Guide

⚠️ Sicherheitswarnungen (CVEs)

Kritische Schwachstellen (Score > 6.5) im Dezember:

IDScoreBeschreibung (Betroffene Versionen)
CVE-2025-536797.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet

FortiSandbox
5.0.0 through 5.0.2,
before 4.4.7 GUI allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
CVE-2025-539497.2An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet

FortiSandbox
5.0.0 through 5.0.2,


FortiSandbox
4.4.0 through 4.4.7,


FortiSandbox
4.2 all versions,


FortiSandbox
4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests.
CVE-2025-597189.8A improper verification of cryptographic signature vulnerability in Fortinet

FortiOS
7.6.0 through 7.6.3,


FortiOS
7.4.0 through 7.4.8,


FortiOS
7.2.0 through 7.2.11,


FortiOS
7.0.0 through 7.0.17,


FortiProxy
7.6.0 through 7.6.3,


FortiProxy
7.4.0 through 7.4.10,


FortiProxy
7.2.0 through 7.2.14,


FortiProxy
7.0.0 through 7.0.21,


FortiSwitchManager
7.2.0 through 7.2.6,


FortiSwitchManager
7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the

FortiCloud
SSO login authentication via a crafted SAML response message.
CVE-2025-597199.8An improper verification of cryptographic signature vulnerability in Fortinet

FortiWeb
8.0.0,


FortiWeb
7.6.0 through 7.6.4,


FortiWeb
7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the

FortiCloud
SSO login authentication via a crafted SAML response message.
CVE-2025-598086.8An unverified password change vulnerability [CWE-620] vulnerability in Fortinet

FortiSOAR
PaaS 7.6.0 through 7.6.2,


FortiSOAR
PaaS 7.5.0 through 7.5.1,


FortiSOAR
PaaS 7.4 all versions,


FortiSOAR
PaaS 7.3 all versions,


FortiSOAR
on-premise 7.6.0 through 7.6.2,


FortiSOAR
on-premise 7.5.0 through 7.5.1,


FortiSOAR
on-premise 7.4 all versions,


FortiSOAR
on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password
CVE-2025-598106.5An improper access control vulnerability in Fortinet

FortiSOAR
PaaS 7.6.0 through 7.6.2,


FortiSOAR
PaaS 7.5.0 through 7.5.1,


FortiSOAR
PaaS 7.4 all versions,


FortiSOAR
PaaS 7.3 all versions,


FortiSOAR
on-premise 7.6.0 through 7.6.2,


FortiSOAR
on-premise 7.5.0 through 7.5.1,


FortiSOAR
on-premise 7.4 all versions,


FortiSOAR
on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests
CVE-2025-600248.8Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet

FortiVoice
7.2.0 through 7.2.2,


FortiVoice
7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands
CVE-2025-641537.2A improper neutralization of special elements used in an os command ('os command injection') in Fortinet

FortiExtender
7.6.0 through 7.6.3,


FortiExtender
7.4.0 through 7.4.7,


FortiExtender
7.2 all versions,


FortiExtender
7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.
CVE-2025-641567.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet

FortiVoice
7.2.0 through 7.2.2,


FortiVoice
7.0.0 through 7.0.7,


FortiVoice
6.4 all versions,


FortiVoice
6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests
CVE-2025-644478.1A reliance on cookies without validation and integrity checking vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.1,


FortiWeb
7.6.0 through 7.6.5,


FortiWeb
7.4.0 through 7.4.10,


FortiWeb
7.2.0 through 7.2.11,


FortiWeb
7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies,
requiring prior knowledge of the

FortiWeb
serial number.