🛡️ Fortinet Monthly Recap | March 2026

Monthly Overview March 2026.

🛡️ Fortinet Monthly Recap | March 2026

📦 Firmware Updates

ProductVersionTypeDocumentation
FORTIADC7.6.6PatchRelease Notes | Admin Guide
FORTIADC7.4.10PatchRelease Notes | Admin Guide
FORTIADCMANAGER7.6.3PatchRelease Notes | Admin Guide
FORTIAIGATE8.0.0MajorRelease Notes | Admin Guide
FORTIAP7.4.7PatchRelease Notes | Admin Guide
FORTIAUTHENTICATOR8.0.2FeatureRelease Notes | Admin Guide
FORTICLIENT7.4.6PatchRelease Notes | Admin Guide
FORTICLIENT7.2.14PatchRelease Notes | Admin Guide
FORTICLIENTEMS7.4.6PatchRelease Notes | Admin Guide
FORTICLIENTEMS7.2.14PatchRelease Notes | Admin Guide
FORTICLIENTLINUX7.4.6PatchRelease Notes | Admin Guide
FORTICLIENTLINUX7.2.14PatchRelease Notes | Admin Guide
FORTICLIENTMAC7.4.6PatchRelease Notes | Admin Guide
FORTICLIENTMAC7.2.14PatchRelease Notes | Admin Guide
FORTIEXTENDER7.4.9PatchRelease Notes | Admin Guide
FORTIFONE7.2.2FeatureRelease Notes | Admin Guide
FORTIFONEANDROID7.2.1PatchRelease Notes | Admin Guide
FORTINAC-F7.6.6PatchRelease Notes | Admin Guide
FORTINDR7.6.4FeatureRelease Notes | Admin Guide
FORTIPAM1.8.2FeatureRelease Notes | Admin Guide
FORTIPORTAL7.4.9PatchRelease Notes | Admin Guide
FORTISANDBOX5.0.6PatchRelease Notes | Admin Guide
FORTISANDBOX4.4.9PatchRelease Notes | Admin Guide
FORTISOAR7.5.3PatchRelease Notes | Admin Guide
FORTISWITCHMANAGER7.0.8PatchRelease Notes | Admin Guide
FORTIVOICE7.4.1PatchRelease Notes | Admin Guide

⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in March:

IDScoreDescription (Affected Versions)
CVE-2026-226278.8A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet

FortiSwitchAXFixed
1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.
CVE-2025-548208.1A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet

FortiManager
7.4.0 through 7.4.2,


FortiManager
7.2.0 through 7.2.10,


FortiManager
6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests,
if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
CVE-2026-240178.1An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.2,


FortiWeb
7.6.0 through 7.6.5,


FortiWeb
7.4.0 through 7.4.10,


FortiWeb
7.2.0 through 7.2.11,


FortiWeb
7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends on the attacker's resources and the password target complexity.
CVE-2026-240187.8A UNIX symbolic link (Symlink) following vulnerability in Fortinet

FortiClientLinux
7.4.0 through 7.4.4,


FortiClientLinux
7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.
CVE-2025-661787.2A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.1,


FortiWeb
7.6.0 through 7.6.5,


FortiWeb
7.4.0 through 7.4.11,


FortiWeb
7.2.0 through 7.2.12,


FortiWeb
7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
CVE-2025-686487.2A use of externally-controlled format string vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.4,


FortiAnalyzer
7.4.0 through 7.4.7,


FortiAnalyzer
7.2 all versions,


FortiAnalyzer
7.0 all versions,


FortiAnalyzer Cloud
7.6.0 through 7.6.4,


FortiAnalyzer Cloud
7.4.0 through 7.4.7,


FortiAnalyzer Cloud
7.2 all versions,


FortiAnalyzer Cloud
7.0 all versions,


FortiManager
7.6.0 through 7.6.4,


FortiManager
7.4.0 through 7.4.7,


FortiManager
7.2 all versions,


FortiManager
7.0 all versions,


FortiManager Cloud
7.6.0 through 7.6.4,


FortiManager Cloud
7.4.0 through 7.4.7,


FortiManager Cloud
7.2 all versions,


FortiManager Cloud
7.0 all versions may allow an attacker to escalate its privileges via specially crafted requests.
CVE-2026-225727.2An authentication bypass using an alternate path or channel vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.3,


FortiAnalyzer
7.4.0 through 7.4.7,


FortiAnalyzer
7.2.2 through 7.2.11,


FortiManager
7.6.0 through 7.6.3,


FortiManager
7.4.0 through 7.4.7,


FortiManager
7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.
CVE-2026-258367.2An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

FortiSandbox Cloud
5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.
CVE-2025-684826.9A improper certificate validation vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.4,


FortiAnalyzer
7.4.0 through 7.4.8,


FortiAnalyzer
7.2 all versions,


FortiAnalyzer
7.0 all versions,


FortiAnalyzer
6.4 all versions,


FortiManager
7.6.0 through 7.6.4,


FortiManager
7.4.0 through 7.4.8,


FortiManager
7.2 all versions,


FortiManager
7.0 all versions,


FortiManager
6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.
CVE-2025-484186.7A hidden functionality vulnerability in Fortinet

FortiAnalyzer
7.6.0 through 7.6.3,


FortiAnalyzer
7.4.0 through 7.4.7,


FortiAnalyzer
7.2.0 through 7.2.10,


FortiAnalyzer
7.0.0 through 7.0.14,


FortiAnalyzer
6.4 all versions,


FortiAnalyzer Cloud
7.6.2,


FortiAnalyzer Cloud
7.4.1 through 7.4.7,


FortiAnalyzer Cloud
7.2.1 through 7.2.10,


FortiAnalyzer Cloud
7.0.1 through 7.0.14,


FortiAnalyzer Cloud
6.4 all versions,


FortiManager
7.6.0 through 7.6.3,


FortiManager
7.4.0 through 7.4.7,


FortiManager
7.2.0 through 7.2.10,


FortiManager
7.0.0 through 7.0.14,


FortiManager
6.4 all versions,


FortiManager Cloud
7.6.2 through 7.6.3,


FortiManager Cloud
7.4.1 through 7.4.7,


FortiManager Cloud
7.2.1 through 7.2.10,


FortiManager Cloud
7.0.1 through 7.0.14,


FortiManager Cloud
6.4 all versions may allow a remote authenticated read-only admin with CLI access to escalate their privilege via use of a hidden command.
CVE-2026-246406.6A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.2,


FortiWeb
7.6.0 through 7.6.6,


FortiWeb
7.4 all versions,


FortiWeb
7.2 all versions,


FortiWeb
7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
CVE-2026-308976.6A stack-based buffer overflow vulnerability in Fortinet

FortiWeb
8.0.0 through 8.0.3,


FortiWeb
7.6.0 through 7.6.6,


FortiWeb
7.4.0 through 7.4.11,


FortiWeb
7.2 all versions,


FortiWeb
7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.
CVE-2026-256896.5An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet

FortiDeceptor
6.2.0,


FortiDeceptor
6.0 all versions,


FortiDeceptor
5.3 all versions,


FortiDeceptor
5.2 all versions,


FortiDeceptor
5.1 all versions,


FortiDeceptor
5.0 all versions,


FortiDeceptor
4.3 all versions,


FortiDeceptor
4.2 all versions,


FortiDeceptor
4.1 all versions,


FortiDeceptor
4.0 all versions may allow a privileged attacker with super-admin profile and CLI access to delete sensitive files via crafted HTTP requests.