> ## Content Index
> Fetch the complete content index at: https://blog.elvatis.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# 🛡️ Fortinet Monthly Recap | March 2026
- URL: https://blog.elvatis.com/fortinet-monthly-recap-march-2026/
- Published: 2026-04-04T16:26:11.000Z
- Updated: 2026-08-31T09:53:09.000Z
- Description: Monthly Overview March 2026.
- Author: E. Kohler
- Tags: Fortinet, MonthlyRecap, March

## 📦 Firmware Updates

| Product                | Version | Type    | Documentation                                                                                                                                                                                 |
| ---------------------- | ------- | ------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **FORTIADC**           | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiadc/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadc/7.6.6/administration-guide)                     |
| **FORTIADC**           | 7.4.10  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiadc/7.4.10/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadc/7.4.10/administration-guide)                   |
| **FORTIADCMANAGER**    | 7.6.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiadcmanager/7.6.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadcmanager/7.6.3/administration-guide)       |
| **FORTIAIGATE**        | 8.0.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortiaigate/8.0.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiaigate/8.0.0/administration-guide)               |
| **FORTIAP**            | 7.4.7   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiap/7.4.7/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiap/7.4.7/administration-guide)                       |
| **FORTIAUTHENTICATOR** | 8.0.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortiauthenticator/8.0.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiauthenticator/8.0.2/administration-guide) |
| **FORTICLIENT**        | 7.4.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlient/7.4.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlient/7.4.6/administration-guide)               |
| **FORTICLIENT**        | 7.2.14  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlient/7.2.14/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlient/7.2.14/administration-guide)             |
| **FORTICLIENTEMS**     | 7.4.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientems/7.4.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientems/7.4.6/administration-guide)         |
| **FORTICLIENTEMS**     | 7.2.14  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientems/7.2.14/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientems/7.2.14/administration-guide)       |
| **FORTICLIENTLINUX**   | 7.4.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientlinux/7.4.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientlinux/7.4.6/administration-guide)     |
| **FORTICLIENTLINUX**   | 7.2.14  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientlinux/7.2.14/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientlinux/7.2.14/administration-guide)   |
| **FORTICLIENTMAC**     | 7.4.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientmac/7.4.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientmac/7.4.6/administration-guide)         |
| **FORTICLIENTMAC**     | 7.2.14  | Patch   | [Release Notes](https://docs.fortinet.com/document/forticlientmac/7.2.14/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/forticlientmac/7.2.14/administration-guide)       |
| **FORTIEXTENDER**      | 7.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiextender/7.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiextender/7.4.9/administration-guide)           |
| **FORTIFONE**          | 7.2.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortifone/7.2.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortifone/7.2.2/administration-guide)                   |
| **FORTIFONEANDROID**   | 7.2.1   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortifoneandroid/7.2.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortifoneandroid/7.2.1/administration-guide)     |
| **FORTINAC-F**         | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortinac-f/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortinac-f/7.6.6/administration-guide)                 |
| **FORTINDR**           | 7.6.4   | Feature | [Release Notes](https://docs.fortinet.com/document/fortindr/7.6.4/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortindr/7.6.4/administration-guide)                     |
| **FORTIPAM**           | 1.8.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortipam/1.8.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortipam/1.8.2/administration-guide)                     |
| **FORTIPORTAL**        | 7.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiportal/7.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiportal/7.4.9/administration-guide)               |
| **FORTISANDBOX**       | 5.0.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisandbox/5.0.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisandbox/5.0.6/administration-guide)             |
| **FORTISANDBOX**       | 4.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisandbox/4.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisandbox/4.4.9/administration-guide)             |
| **FORTISOAR**          | 7.5.3   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisoar/7.5.3/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisoar/7.5.3/administration-guide)                   |
| **FORTISWITCHMANAGER** | 7.0.8   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitchmanager/7.0.8/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchmanager/7.0.8/administration-guide) |
| **FORTIVOICE**         | 7.4.1   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortivoice/7.4.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortivoice/7.4.1/administration-guide)                 |

## ⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in March:

| ID                                                                | Score | Description (Affected Versions)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ----------------------------------------------------------------- | ----- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2026-22627](https://nvd.nist.gov/vuln/detail/CVE-2026-22627) | 8.8   | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet **FortiSwitchAXFixed** 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| [CVE-2025-54820](https://nvd.nist.gov/vuln/detail/CVE-2025-54820) | 8.1   | A Stack-based Buffer Overflow vulnerability \[CWE-121\] vulnerability in Fortinet **FortiManager** 7.4.0 through 7.4.2,**FortiManager** 7.2.0 through 7.2.10,**FortiManager** 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests,if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| [CVE-2026-24017](https://nvd.nist.gov/vuln/detail/CVE-2026-24017) | 8.1   | An Improper Control of Interaction Frequency vulnerability \[CWE-799\] vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.2,**FortiWeb** 7.6.0 through 7.6.5,**FortiWeb** 7.4.0 through 7.4.10,**FortiWeb** 7.2.0 through 7.2.11,**FortiWeb** 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends on the attacker's resources and the password target complexity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| [CVE-2026-24018](https://nvd.nist.gov/vuln/detail/CVE-2026-24018) | 7.8   | A UNIX symbolic link (Symlink) following vulnerability in Fortinet **FortiClientLinux** 7.4.0 through 7.4.4,**FortiClientLinux** 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| [CVE-2025-66178](https://nvd.nist.gov/vuln/detail/CVE-2025-66178) | 7.2   | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.1,**FortiWeb** 7.6.0 through 7.6.5,**FortiWeb** 7.4.0 through 7.4.11,**FortiWeb** 7.2.0 through 7.2.12,**FortiWeb** 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| [CVE-2025-68648](https://nvd.nist.gov/vuln/detail/CVE-2025-68648) | 7.2   | A use of externally-controlled format string vulnerability in Fortinet **FortiAnalyzer** 7.6.0 through 7.6.4,**FortiAnalyzer** 7.4.0 through 7.4.7,**FortiAnalyzer** 7.2 all versions,**FortiAnalyzer** 7.0 all versions,**FortiAnalyzer Cloud** 7.6.0 through 7.6.4,**FortiAnalyzer Cloud** 7.4.0 through 7.4.7,**FortiAnalyzer Cloud** 7.2 all versions,**FortiAnalyzer Cloud** 7.0 all versions,**FortiManager** 7.6.0 through 7.6.4,**FortiManager** 7.4.0 through 7.4.7,**FortiManager** 7.2 all versions,**FortiManager** 7.0 all versions,**FortiManager Cloud** 7.6.0 through 7.6.4,**FortiManager Cloud** 7.4.0 through 7.4.7,**FortiManager Cloud** 7.2 all versions,**FortiManager Cloud** 7.0 all versions may allow an attacker to escalate its privileges via specially crafted requests.                                                                                                                                                                                            |
| [CVE-2026-22572](https://nvd.nist.gov/vuln/detail/CVE-2026-22572) | 7.2   | An authentication bypass using an alternate path or channel vulnerability in Fortinet **FortiAnalyzer** 7.6.0 through 7.6.3,**FortiAnalyzer** 7.4.0 through 7.4.7,**FortiAnalyzer** 7.2.2 through 7.2.11,**FortiManager** 7.6.0 through 7.6.3,**FortiManager** 7.4.0 through 7.4.7,**FortiManager** 7.2.2 through 7.2.11 may allow an attacker with knowledge of the admins password to bypass multifactor authentication checks via submitting multiple crafted requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| [CVE-2026-25836](https://nvd.nist.gov/vuln/detail/CVE-2026-25836) | 7.2   | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet **FortiSandbox Cloud** 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| [CVE-2025-68482](https://nvd.nist.gov/vuln/detail/CVE-2025-68482) | 6.9   | A improper certificate validation vulnerability in Fortinet **FortiAnalyzer** 7.6.0 through 7.6.4,**FortiAnalyzer** 7.4.0 through 7.4.8,**FortiAnalyzer** 7.2 all versions,**FortiAnalyzer** 7.0 all versions,**FortiAnalyzer** 6.4 all versions,**FortiManager** 7.6.0 through 7.6.4,**FortiManager** 7.4.0 through 7.4.8,**FortiManager** 7.2 all versions,**FortiManager** 7.0 all versions,**FortiManager** 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle \[MiTM\] attack.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| [CVE-2025-48418](https://nvd.nist.gov/vuln/detail/CVE-2025-48418) | 6.7   | A hidden functionality vulnerability in Fortinet **FortiAnalyzer** 7.6.0 through 7.6.3,**FortiAnalyzer** 7.4.0 through 7.4.7,**FortiAnalyzer** 7.2.0 through 7.2.10,**FortiAnalyzer** 7.0.0 through 7.0.14,**FortiAnalyzer** 6.4 all versions,**FortiAnalyzer Cloud** 7.6.2,**FortiAnalyzer Cloud** 7.4.1 through 7.4.7,**FortiAnalyzer Cloud** 7.2.1 through 7.2.10,**FortiAnalyzer Cloud** 7.0.1 through 7.0.14,**FortiAnalyzer Cloud** 6.4 all versions,**FortiManager** 7.6.0 through 7.6.3,**FortiManager** 7.4.0 through 7.4.7,**FortiManager** 7.2.0 through 7.2.10,**FortiManager** 7.0.0 through 7.0.14,**FortiManager** 6.4 all versions,**FortiManager Cloud** 7.6.2 through 7.6.3,**FortiManager Cloud** 7.4.1 through 7.4.7,**FortiManager Cloud** 7.2.1 through 7.2.10,**FortiManager Cloud** 7.0.1 through 7.0.14,**FortiManager Cloud** 6.4 all versions may allow a remote authenticated read-only admin with CLI access to escalate their privilege via use of a hidden command. |
| [CVE-2026-24640](https://nvd.nist.gov/vuln/detail/CVE-2026-24640) | 6.6   | A Stack-based Buffer Overflow vulnerability \[CWE-121\] vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.2,**FortiWeb** 7.6.0 through 7.6.6,**FortiWeb** 7.4 all versions,**FortiWeb** 7.2 all versions,**FortiWeb** 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| [CVE-2026-30897](https://nvd.nist.gov/vuln/detail/CVE-2026-30897) | 6.6   | A stack-based buffer overflow vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.3,**FortiWeb** 7.6.0 through 7.6.6,**FortiWeb** 7.4.0 through 7.4.11,**FortiWeb** 7.2 all versions,**FortiWeb** 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| [CVE-2026-25689](https://nvd.nist.gov/vuln/detail/CVE-2026-25689) | 6.5   | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet **FortiDeceptor** 6.2.0,**FortiDeceptor** 6.0 all versions,**FortiDeceptor** 5.3 all versions,**FortiDeceptor** 5.2 all versions,**FortiDeceptor** 5.1 all versions,**FortiDeceptor** 5.0 all versions,**FortiDeceptor** 4.3 all versions,**FortiDeceptor** 4.2 all versions,**FortiDeceptor** 4.1 all versions,**FortiDeceptor** 4.0 all versions may allow a privileged attacker with super-admin profile and CLI access to delete sensitive files via crafted HTTP requests.                                                                                                                                                                                                                                                                                                                                                                                                    |