🛡️ Fortinet Monthly Recap | May 2026

Monthly Overview May 2026.

🛡️ Fortinet Monthly Recap | May 2026

📦 Firmware Updates

ProductVersionTypeDocumentation
COLLECTORWINDOWS6.2.0MajorRelease Notes | Admin Guide
FORTIADC7.6.7PatchRelease Notes | Admin Guide
FORTIADC7.4.11PatchRelease Notes | Admin Guide
FORTIADCMANAGER8.0.0MajorRelease Notes | Admin Guide
FORTIAIOPS3.4.0MajorRelease Notes | Admin Guide
FORTIANALYZER7.4.11PatchRelease Notes | Admin Guide
FORTIANALYZER-BIGDATA7.2.12PatchRelease Notes | Admin Guide
FORTIAP7.6.5PatchRelease Notes | Admin Guide
FORTIAUTHENTICATOR6.6.10PatchRelease Notes | Admin Guide
FORTIMAIL8.0.0MajorRelease Notes | Admin Guide
FORTIMAIL7.6.5PatchRelease Notes | Admin Guide
FORTIMANAGER7.4.11PatchRelease Notes | Admin Guide
FORTIMONITORONSIGHT7.2.11PatchRelease Notes | Admin Guide
FORTIOS7.4.12PatchRelease Notes | Admin Guide
FORTIOS7.4.8PatchRelease Notes | Admin Guide
FORTIPAM1.9.0MajorRelease Notes | Admin Guide
FORTIPORTAL7.4.11PatchRelease Notes | Admin Guide
FORTIPORTAL7.2.9PatchRelease Notes | Admin Guide
FORTIPORTAL7.0.14PatchRelease Notes | Admin Guide
FORTIRECORDER7.2.11PatchRelease Notes | Admin Guide
FORTISIEM7.5.1PatchRelease Notes | Admin Guide
FORTISIEMWINDOWSAGENT7.5.1PatchRelease Notes | Admin Guide
FORTISWITCH8.0.0MajorRelease Notes | Admin Guide
FORTIWEBMANAGER8.0.1PatchRelease Notes | Admin Guide

⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in May:

IDScoreDescription (Affected Versions)
CVE-2026-260839.8A missing authorization vulnerability in Fortinet

FortiSandbox
5.0.0 through 5.0.1,


FortiSandbox
4.4.0 through 4.4.8,


FortiSandbox Cloud
5.0.2 through 5.0.5,


FortiSandbox
PaaS 23.4 all versions,


FortiSandbox
PaaS 23.3 all versions,


FortiSandbox
PaaS 23.1 all versions,


FortiSandbox
PaaS 22.2 all versions,


FortiSandbox
PaaS 22.1 all versions,


FortiSandbox
PaaS 21.4 all versions,


FortiSandbox
PaaS 21.3 all versions,


FortiSandbox
PaaS 5.0.0 through 5.0.1,


FortiSandbox
PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.
CVE-2026-442779.8A improper access control vulnerability in Fortinet

FortiAuthenticator
8.0.2,


FortiAuthenticator
8.0.0,


FortiAuthenticator
6.6.0 through 6.6.8,


FortiAuthenticator
6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.
CVE-2025-538448.8A out-of-bounds write vulnerability in Fortinet

FortiOS
7.6.0 through 7.6.3,


FortiOS
7.4.0 through 7.4.8,


FortiOS
7.2.0 through 7.2.11

allows attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2025-536817.2An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet

FortiMail
7.6.0 through 7.6.3,


FortiMail
7.4.0 through 7.4.5,


FortiMail
7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
CVE-2025-536806.7An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet

FortiAP
7.6.0 through 7.6.2,


FortiAP
7.4.0 through 7.4.5,


FortiAP
7.2 all versions,


FortiAP
7.0 all versions,


FortiAP
6.4 all versions,


FortiAP
-U 7.0.0 through 7.0.5,


FortiAP
-U 6.2 all versions,


FortiAP
-W2 7.4.0 through 7.4.4,


FortiAP
-W2 7.2 all versions,


FortiAP
-W2 7.0 all versions allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
CVE-2025-538706.7An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

FortiAP
7.6.0 through 7.6.2,


FortiAP
7.4.0 through 7.4.5,


FortiAP
7.2 all versions,


FortiAP
7.0 all versions,


FortiAP
6.4 all versions,


FortiAP
-W2 7.4.0 through 7.4.4,


FortiAP
-W2 7.2 all versions,


FortiAP
-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.