> ## Content Index
> Fetch the complete content index at: https://blog.elvatis.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# 🛡️ Fortinet Monthly Recap | November 2025
- URL: https://blog.elvatis.com/fortinet-monthly-recap-november-2025/
- Published: 2025-12-02T12:37:03.000Z
- Updated: 2026-08-31T09:53:32.000Z
- Description: Monthly Overview November 2025.
- Author: E. Kohler
- Tags: Fortinet, Monthly Recap, security, Cybersecurity, Vulnerability Management, November

## 📦 Firmware Updates

| Product                   | Version | Type    | Documentation                                                                                                                                                                                         |
| ------------------------- | ------- | ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **FORTIADC**              | 7.4.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiadc/7.4.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiadc/7.4.9/administration-guide)                             |
| **FORTIANALYZER**         | 7.0.15  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer/7.0.15/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer/7.0.15/administration-guide)                 |
| **FORTIANALYZER-BIGDATA** | 7.2.11  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortianalyzer-bigdata/7.2.11/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortianalyzer-bigdata/7.2.11/administration-guide) |
| **FORTIDDOS-F**           | 7.2.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortiddos-f/7.2.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiddos-f/7.2.2/administration-guide)                       |
| **FORTIMANAGER**          | 7.0.15  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortimanager/7.0.15/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortimanager/7.0.15/administration-guide)                   |
| **FORTINDR**              | 7.4.10  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortindr/7.4.10/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortindr/7.4.10/administration-guide)                           |
| **FORTIOS**               | 7.0.18  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortigate/7.0.18/fortios-release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortigate/7.0.18/administration-guide)                 |
| **FORTIOS-6K7K**          | 7.0.18  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortios-6k7k/7.0.18/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortios-6k7k/7.0.18/administration-guide)                   |
| **FORTIPAM**              | 1.7.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortipam/1.7.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortipam/1.7.2/administration-guide)                             |
| **FORTIPORTAL**           | 7.0.13  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiportal/7.0.13/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiportal/7.0.13/administration-guide)                     |
| **FORTIPROXY**            | 7.4.12  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiproxy/7.4.12/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiproxy/7.4.12/administration-guide)                       |
| **FORTISANDBOX**          | 5.0.5   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisandbox/5.0.5/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisandbox/5.0.5/administration-guide)                     |
| **FORTISIEM**             | 7.1.9   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortisiem/7.1.9/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisiem/7.1.9/administration-guide)                           |
| **FORTISRA**              | 1.7.2   | Feature | [Release Notes](https://docs.fortinet.com/document/fortisra/1.7.2/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortisra/1.7.2/administration-guide)                             |
| **FORTISWITCHAXCHASSIS**  | 1.0.0   | Major   | [Release Notes](https://docs.fortinet.com/document/fortiswitchaxchassis/1.0.0/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchaxchassis/1.0.0/administration-guide)     |
| **FORTISWITCHNMS**        | 1.13.1  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiswitchnms/1.13.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiswitchnms/1.13.1/administration-guide)               |
| **FORTITELEMETRYAGENT**   | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortitelemetryagent/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortitelemetryagent/7.6.6/administration-guide)       |
| **FORTITESTER**           | 7.6.1   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortitester/7.6.1/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortitester/7.6.1/administration-guide)                       |
| **FORTIWEB**              | 7.6.6   | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiweb/7.6.6/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiweb/7.6.6/administration-guide)                             |
| **FORTIWEB**              | 7.4.11  | Patch   | [Release Notes](https://docs.fortinet.com/document/fortiweb/7.4.11/release-notes) \| [Admin Guide](https://docs.fortinet.com/document/fortiweb/7.4.11/administration-guide)                           |

## ⚠️ Security Advisories (CVEs)

Critical vulnerabilities (Score > 6.5) in November:

| ID                                                                | Score | Description (Affected Versions)                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------------------- | ----- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2025-64446](https://nvd.nist.gov/vuln/detail/CVE-2025-64446) | 9.8   | A relative path traversal vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.1,**FortiWeb** 7.6.0 through 7.6.4,**FortiWeb** 7.4.0 through 7.4.9,**FortiWeb** 7.2.0 through 7.2.11,**FortiWeb** 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.                                                                                                                         |
| [CVE-2025-46373](https://nvd.nist.gov/vuln/detail/CVE-2025-46373) | 7.8   | A Heap-based Buffer Overflow vulnerability \[CWE-122\] in Fortinet **FortiClientWindows** 7.4.0 through 7.4.3,**FortiClientWindows** 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to execute arbitrary code or commands via "fortips\_74.sys". The attacker would need to bypass the Windows heap integrity protections                                                                                                                    |
| [CVE-2025-47761](https://nvd.nist.gov/vuln/detail/CVE-2025-47761) | 7.8   | An Exposed IOCTL with Insufficient Access Control vulnerability \[CWE-782\] in Fortinet **FortiClientWindows** 7.4.0 through 7.4.3,**FortiClientWindows** 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips driver. Success of the attack would require bypassing the Windows memory protections such as Heap integrity and HSP. In addition,it requires a valid and running VPN IPSec connection.           |
| [CVE-2025-53843](https://nvd.nist.gov/vuln/detail/CVE-2025-53843) | 7.5   | A stack-based buffer overflow vulnerability in Fortinet **FortiOS** 7.6.0 through 7.6.3,**FortiOS** 7.4.0 through 7.4.8,**FortiOS** 7.2 all versions,**FortiOS** 7.0 all versions,**FortiOS** 6.4 all versionsallows attacker to execute unauthorized code or commands via specially crafted packets                                                                                                                                                          |
| [CVE-2025-58034](https://nvd.nist.gov/vuln/detail/CVE-2025-58034) | 7.2   | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability \[CWE-78\] vulnerability in Fortinet **FortiWeb** 8.0.0 through 8.0.1,**FortiWeb** 7.6.0 through 7.6.5,**FortiWeb** 7.4.0 through 7.4.10,**FortiWeb** 7.2.0 through 7.2.11,**FortiWeb** 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands. |
| [CVE-2025-58413](https://nvd.nist.gov/vuln/detail/CVE-2025-58413) | 7.5   | A stack-based buffer overflow vulnerability in Fortinet **FortiOS** 7.6.0 through 7.6.3,**FortiOS** 7.4.0 through 7.4.8,**FortiOS** 7.2 all versions,**FortiOS** 7.0 all versions,**FortiOS** 6.4 all versions,**FortiOS** 6.2 all versions,**FortiOS** 6.0 all versions,**FortiSASE** 25.3.ballows attacker to execute unauthorized code or commands via specially crafted packets                                                                           |
| [CVE-2025-58692](https://nvd.nist.gov/vuln/detail/CVE-2025-58692) | 8.8   | An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability \[CWE-89\] in Fortinet **FortiVoice** 7.2.0 through 7.2.2,**FortiVoice** 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.                                                                                                                                 |