Product Security

The FortiGuard Product Security incident Response Team (PSIRT) responds to vulnerability reports from customers, partners and researchers. Upon submission of a product vulnerability, the FortiGuard PSIRT will triage the issue and work with our developers to ensure a timely resolution.

To contact the FortiGuard PSIRT team about vulnerabilities in Fortinet products or services, please email [email protected]. When reporting a vulnerability, we strongly encourage you to use PGP to encrypt your communications. Our public key can be found here.


Latest Advisories

FortiOS flow-mode detection bypass under certain conditions

Posted: 22 November 2016

Implementation of CTR_DRBG RNG in FortiOS 4.3

Posted: 22 November 2016

Blacknurse ICMP DoS attack

Posted: 15 November 2016

Linux Kernel Dirty Cow Vulnerability

Posted: 09 November 2016

FortiWLC Undocumented Hardcoded core Account

Posted: 09 November 2016

FortiAnalyzer and FortiManager stored XSS vulnerability in report filters

Posted: 05 October 2016

FortiWLC PAM.log authenticated user information exposure

Posted: 30 September 2016

FortiWLC Undocumented Hardcoded Rsync Account

Posted: 30 September 2016

FortiDDoS Command Injection Vulnerability Announcement

Posted: 28 September 2016

OpenSSL Advisory - May 2016

Posted: 22 September 2016

FortiClient DLL Hijacking vulnerability

Posted: 12 September 2016

FortiClient Unencrypted Password Vulnerability

Posted: 12 September 2016

FortiWAN Multiple Vulnerabilities

Posted: 07 September 2016

Cookie Parser Buffer Overflow Vulnerability

Posted: 17 August 2016

FortiCloud Cross Site Script Persistent Web Vulnerabilities

Posted: 09 August 2016

FortiVoice 5.0 Filter Bypass & Persistent Web Vulnerabilities

Posted: 09 August 2016

FortiManager and FortiAnalyzer Persistent XSS vulnerability

Posted: 09 August 2016

FortiManager and FortiAnalyzer XSS vulnerability

Posted: 09 August 2016

FortiManager and FortiAnalyzer Client Side XSS vulnerability

Posted: 09 August 2016

FortiManager and FortiAnalyzer Persistent XSS vulnerability

Posted: 14 July 2016

OpenSSL Advisory - January 2016

Posted: 12 July 2016

FortiSwitch rest_admin account exposed under specific conditions

Posted: 11 July 2016

FortiWeb CSRF Vulnerability

Posted: 23 June 2016

Fortiweb path traversal vulnerability

Posted: 26 May 2016

RSA-CRT key leak under certain conditions

Posted: 16 May 2016

SAM and LSAD remote protocols man in the middle vulnerability (Badlock)

Posted: 14 April 2016

FortiOS open redirect vulnerability

Posted: 16 March 2016

DHCP Hostname HTML Injection

Posted: 16 March 2016

Glibc getaddrinfo() stack-overflow

Posted: 25 February 2016

Multiple Products SSH Undocumented Login Vulnerability

Posted: 12 January 2016