🛡️ Fortinet Monthly Recap | Januar 2026

Monatsübersicht Januar 2026.

📦 Firmware Updates

ProduktVersionTypDokumentation
FORTIANALYZER7.0.16PatchRelease Notes | Admin Guide
FORTIMANAGER7.0.16PatchRelease Notes | Admin Guide
FORTIOS7.0.19PatchRelease Notes | Admin Guide
FORTIFONE7.2.1PatchRelease Notes | Admin Guide
FORTIANALYZER7.2.12PatchRelease Notes | Admin Guide
FORTIMANAGER7.2.12PatchRelease Notes | Admin Guide
FORTIRECORDER7.2.8PatchRelease Notes | Admin Guide
FORTIOS7.2.13PatchRelease Notes | Admin Guide
FORTIDDOS-F7.2.4FeatureRelease Notes | Admin Guide
FORTIANALYZER7.6.6PatchRelease Notes | Admin Guide
FORTIOS7.6.6PatchRelease Notes | Admin Guide
FORTIMANAGER7.6.6PatchRelease Notes | Admin Guide
FORTIANALYZER7.4.10PatchRelease Notes | Admin Guide
FORTIMANAGER7.4.10PatchRelease Notes | Admin Guide
FORTIOS7.4.11PatchRelease Notes | Admin Guide
FORTIANALYZER7.4.9PatchRelease Notes | Admin Guide
FORTIMANAGER7.4.9PatchRelease Notes | Admin Guide
FORTIOS7.4.10PatchRelease Notes | Admin Guide
FORTICLIENTEMS7.2.13PatchRelease Notes | Admin Guide
FORTICLIENT7.2.13PatchRelease Notes | Admin Guide
FORTICLIENTLINUX7.2.13PatchRelease Notes | Admin Guide
FORTICLIENTMAC7.2.13PatchRelease Notes | Admin Guide
FORTISWITCHMANAGER7.2.8PatchRelease Notes | Admin Guide
FORTIDDOS-F7.2.3PatchRelease Notes | Admin Guide
FORTISWITCHAXCHASSIS1.0.1PatchRelease Notes | Admin Guide
FORTISWITCHNMS1.13.2FeatureRelease Notes | Admin Guide
FORTISIEMWINDOWSAGENT7.5.0MajorRelease Notes | Admin Guide
FORTISWITCH7.0.12PatchRelease Notes | Admin Guide

⚠️ Sicherheitswarnungen (CVEs)

Kritische Schwachstellen (Score > 6.5) im Januar:

IDScoreBeschreibung (Betroffene Versionen)
CVE-2025-252498.1A heap-based buffer overflow vulnerability in Fortinet

FortiOS
7.6.0 through 7.6.3,


FortiOS
7.4.0 through 7.4.8,


FortiOS
7.2.0 through 7.2.11,


FortiOS
7.0.0 through 7.0.17,


FortiOS
6.4.0 through 6.4.16,


FortiSwitchManager
7.2.0 through 7.2.6,


FortiSwitchManager
7.0.0 through 7.0.5

allows attacker to execute unauthorized code or commands via specially crafted packets
CVE-2025-478559.8An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet

FortiFone
7.0.0 through 7.0.1,


FortiFone
3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.
CVE-2025-586936.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet

FortiVoice
7.2.0 through 7.2.2,


FortiVoice
7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
CVE-2025-599227.2An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet

FortiClientEMS
7.4.3 through 7.4.4,


FortiClientEMS
7.4.0 through 7.4.1,


FortiClientEMS
7.2.0 through 7.2.10,


FortiClientEMS
7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-641559.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

FortiSIEM
7.4.0,


FortiSIEM
7.3.0 through 7.3.4,


FortiSIEM
7.1.0 through 7.1.8,


FortiSIEM
7.0.0 through 7.0.4,


FortiSIEM
6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
CVE-2026-248589.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.5,


FortiAnalyzer
7.4.0 through 7.4.9,


FortiAnalyzer
7.2.0 through 7.2.11,


FortiAnalyzer
7.0.0 through 7.0.15,


FortiManager
7.6.0 through 7.6.5,


FortiManager
7.4.0 through 7.4.9,


FortiManager
7.2.0 through 7.2.11,


FortiManager
7.0.0 through 7.0.15,


FortiOS
7.6.0 through 7.6.5,


FortiOS
7.4.0 through 7.4.10,


FortiOS
7.2.0 through 7.2.12,


FortiOS
7.0.0 through 7.0.18,


FortiProxy
7.6.0 through 7.6.4,


FortiProxy
7.4.0 through 7.4.12,


FortiProxy
7.2.0 through 7.2.15,


FortiProxy
7.0.0 through 7.0.22,


FortiWeb
8.0.0 through 8.0.3,


FortiWeb
7.6.0 through 7.6.6,


FortiWeb
7.4.0 through 7.4.11 may allow an attacker with a

FortiCloud
account and a registered device to log into other devices registered to other accounts,
if

FortiCloud
SSO authentication is enabled on those devices.