> ## Content Index
> Fetch the complete content index at: https://blog.elvatis.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# 🛡️ Fortinet Monthly Recap | January 2026
- URL: https://blog.elvatis.com/fortinet-monthly-recap-january-2026/
- Published: 2026-02-05T12:28:36.000Z
- Updated: 2026-08-31T09:53:28.000Z
- Description: Monthly Overview January 2026.
- Author: E. Kohler
- Tags: Fortinet, Monthly Recap, security, Cybersecurity, Vulnerability Management, January

## 📦 Firmware Updates

| Product                   | Version | Type    | Documentation                                                                                                                                                                                       |
| ------------------------- | ------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **FORTIANALYZER**         | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.6.6/administration-guide)                 |
| **FORTIANALYZER**         | 7.4.10  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.4.10/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.4.10/administration-guide)               |
| **FORTIANALYZER**         | 7.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.4.9/administration-guide)                 |
| **FORTIANALYZER**         | 7.2.12  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.2.12/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.2.12/administration-guide)               |
| **FORTIANALYZER**         | 7.0.16  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.0.16/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.0.16/administration-guide)               |
| **FORTICLIENT**           | 7.2.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlient/7.2.13/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlient/7.2.13/administration-guide)                   |
| **FORTICLIENTEMS**        | 7.2.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientems/7.2.13/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientems/7.2.13/administration-guide)             |
| **FORTICLIENTLINUX**      | 7.2.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientlinux/7.2.13/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientlinux/7.2.13/administration-guide)         |
| **FORTICLIENTMAC**        | 7.2.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientmac/7.2.13/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientmac/7.2.13/administration-guide)             |
| **FORTIDDOS-F**           | 7.2.4   | Feature | [Release Notes](https://docs.fortinet.com/document/fortiddos-f/7.2.4/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiddos-f/7.2.4/administration-guide)                     |
| **FORTIDDOS-F**           | 7.2.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiddos-f/7.2.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiddos-f/7.2.3/administration-guide)                     |
| **FORTIFONE**             | 7.2.1   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortifone/7.2.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortifone/7.2.1/administration-guide)                         |
| **FORTIMANAGER**          | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.6.6/administration-guide)                   |
| **FORTIMANAGER**          | 7.4.10  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.4.10/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.4.10/administration-guide)                 |
| **FORTIMANAGER**          | 7.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.4.9/administration-guide)                   |
| **FORTIMANAGER**          | 7.2.12  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.2.12/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.2.12/administration-guide)                 |
| **FORTIMANAGER**          | 7.0.16  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.0.16/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.0.16/administration-guide)                 |
| **FORTIOS**               | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.6.6/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide)                 |
| **FORTIOS**               | 7.4.11  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.4.11/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.4.11/administration-guide)               |
| **FORTIOS**               | 7.4.10  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.4.10/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.4.10/administration-guide)               |
| **FORTIOS**               | 7.2.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.2.13/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.2.13/administration-guide)               |
| **FORTIOS**               | 7.0.19  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.0.19/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.0.19/administration-guide)               |
| **FORTIRECORDER**         | 7.2.8   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortirecorder/7.2.8/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortirecorder/7.2.8/administration-guide)                 |
| **FORTISIEMWINDOWSAGENT** | 7.5.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortisiemwindowsagent/7.5.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisiemwindowsagent/7.5.0/administration-guide) |
| **FORTISWITCH**           | 7.0.12  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitch/7.0.12/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitch/7.0.12/administration-guide)                   |
| **FORTISWITCHAXCHASSIS**  | 1.0.1   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitchaxchassis/1.0.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchaxchassis/1.0.1/administration-guide)   |
| **FORTISWITCHMANAGER**    | 7.2.8   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitchmanager/7.2.8/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchmanager/7.2.8/administration-guide)       |
| **FORTISWITCHNMS**        | 1.13.2  | Feature | [Release Notes](https://docs.fortinet.com/document/fortiswitchnms/1.13.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchnms/1.13.2/administration-guide)             |

## ⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in January:

| ID                                                                | Score | Description (Affected Versions)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ----------------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2025-25249](https://nvd.nist.gov/vuln/detail/CVE-2025-25249) | 8.1   | A heap-based buffer overflow vulnerability in Fortinet **FortiOS** 7.6.0 through 7.6.3,**FortiOS** 7.4.0 through 7.4.8,**FortiOS** 7.2.0 through 7.2.11,**FortiOS** 7.0.0 through 7.0.17,**FortiOS** 6.4.0 through 6.4.16,**FortiSwitchManager** 7.2.0 through 7.2.6,**FortiSwitchManager** 7.0.0 through 7.0.5allows attacker to execute unauthorized code or commands via specially crafted packets                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| [CVE-2025-47855](https://nvd.nist.gov/vuln/detail/CVE-2025-47855) | 9.8   | An exposure of sensitive information to an unauthorized actor \[CWE-200\] vulnerability in Fortinet **FortiFone** 7.0.0 through 7.0.1,**FortiFone** 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| [CVE-2025-58693](https://nvd.nist.gov/vuln/detail/CVE-2025-58693) | 6.5   | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet **FortiVoice** 7.2.0 through 7.2.2,**FortiVoice** 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| [CVE-2025-59922](https://nvd.nist.gov/vuln/detail/CVE-2025-59922) | 7.2   | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability \[CWE-89\] vulnerability in Fortinet **FortiClientEMS** 7.4.3 through 7.4.4,**FortiClientEMS** 7.4.0 through 7.4.1,**FortiClientEMS** 7.2.0 through 7.2.10,**FortiClientEMS** 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| [CVE-2025-64155](https://nvd.nist.gov/vuln/detail/CVE-2025-64155) | 9.8   | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet **FortiSIEM** 7.4.0,**FortiSIEM** 7.3.0 through 7.3.4,**FortiSIEM** 7.1.0 through 7.1.8,**FortiSIEM** 7.0.0 through 7.0.4,**FortiSIEM** 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| [CVE-2026-24858](https://nvd.nist.gov/vuln/detail/CVE-2026-24858) | 9.8   | An Authentication Bypass Using an Alternate Path or Channel vulnerability \[CWE-288\] vulnerability in Fortinet **FortiAnalyzer** 7.6.0 through 7.6.5,**FortiAnalyzer** 7.4.0 through 7.4.9,**FortiAnalyzer** 7.2.0 through 7.2.11,**FortiAnalyzer** 7.0.0 through 7.0.15,**FortiManager** 7.6.0 through 7.6.5,**FortiManager** 7.4.0 through 7.4.9,**FortiManager** 7.2.0 through 7.2.11,**FortiManager** 7.0.0 through 7.0.15,**FortiOS** 7.6.0 through 7.6.5,**FortiOS** 7.4.0 through 7.4.10,**FortiOS** 7.2.0 through 7.2.12,**FortiOS** 7.0.0 through 7.0.18,**FortiProxy** 7.6.0 through 7.6.4,**FortiProxy** 7.4.0 through 7.4.12,**FortiProxy** 7.2.0 through 7.2.15,**FortiProxy** 7.0.0 through 7.0.22,**FortiWeb** 8.0.0 through 8.0.3,**FortiWeb** 7.6.0 through 7.6.6,**FortiWeb** 7.4.0 through 7.4.11 may allow an attacker with a **FortiCloud** account and a registered device to log into other devices registered to other accounts,if **FortiCloud** SSO authentication is enabled on those devices. |