Skip to content

VendorsFortinet

FortinetFortiOS

28records45rowslast change2026-08-14as of the 2026-09-07 snapshot

Rows per week, last 26 weeks

19 rows in the last 26 weeks, 0 in the week to 2026-09-070 this week

Rows, not records: one record that changed for four products is four rows and one record.

Every change, newest first

lines 1 to 20 of 21 · standing on 44 of 45 rows
Every counted change to a CVE or CISA KEV record naming Fortinet and FortiOS, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEWhat the record says now
2025-04-07 to2026-08-14Ransomware use confirmedstated at publication Unknown, now states Known
2026-08-14Ransomware use confirmedCVE-2019-5591stated at publication Unknown, now states Known
2025-07-14Ransomware use confirmedCVE-2019-6693stated at publication Unknown, now states Known
2 more rows in this change are not listed here. Open all 4 rows
2026-07-27Added to CISA KEVCVE-2025-68686listed by CISA 2026-07-27federal fix due 2026-08-10
2026-07-16Affected range extendedCVE-2026-59840stated at publication 7.6.2, now states 7.6.3
2026-06-09 to2026-07-08Affected range extendedstated at publication 7.2.12, now states 7.2.13
2026-07-08Affected range extendedCVE-2025-31366stated at publication 7.2.12, now states 7.2.13
2026-07-08Affected range extendedCVE-2025-47890stated at publication 7.2.12, now states 7.2.13
2 more rows in this change are not listed here. Open all 4 rows
2026-06-09 to2026-07-08Affected range extendedstated at publication 7.0.17, now states 7.0.19
2026-07-08Affected range extendedCVE-2025-31366stated at publication 7.0.17, now states 7.0.19
2026-07-08Affected range extendedCVE-2025-47890stated at publication 7.0.17, now states 7.0.19
2 more rows in this change are not listed here. Open all 4 rows
2026-06-09 to2026-06-23Affected range extendedstated at publication 7.4.9, now states 7.4.11
2026-06-23Affected range extendedCVE-2025-54821stated at publication 7.4.9, now states 7.4.11
2026-06-09Affected range extendedCVE-2025-31514stated at publication 7.4.9, now states 7.4.11
2026-02-10 to2026-06-23Affected range extendedstated at publication 7.0.18, now states 7.0.19
2026-06-23Affected range extendedCVE-2025-54821stated at publication 7.0.18, now states 7.0.19
2026-02-10Affected range extendedCVE-2025-62631stated at publication 7.0.18, now states 7.0.19
2026-05-12 to2026-06-23Affected range extendedstated at publication 7.2.11, now states 7.2.13
2026-06-23Affected range extendedCVE-2025-25250stated at publication 7.2.11, now states 7.2.13
2026-05-12Affected range extendedCVE-2025-62631stated at publication 7.2.11, now states 7.2.13
2026-01-14 to2026-06-12Affected range extendedstated at publication 6.2.16, now states 6.2.17
2026-06-12Affected range extendedCVE-2023-36640stated at publication 6.2.16, now states 6.2.17
2026-06-12Affected range extendedCVE-2023-45583stated at publication 6.2.16, now states 6.2.17
1 more row in this change is not listed here. Open all 3 rows
2025-12-19 to2026-06-12Affected range extendedstated at publication 6.4.15, now states 6.4.16
2026-06-12Affected range extendedCVE-2023-45583stated at publication 6.4.15, now states 6.4.16
2026-01-14Affected range extendedCVE-2023-40721stated at publication 6.4.15, now states 6.4.16
1 more row in this change is not listed here. Open all 3 rows
2026-01-14Affected range extendedCVE-2023-29175stated at publication 6.2.15, now states 6.2.17
2026-01-14Affected range extendedCVE-2023-29175stated at publication 6.4.13, now states 6.4.16
2024-10-18 to2026-01-14Affected range extendedstated at publication 6.0.17, now states 6.0.18
2026-01-14Affected range extendedCVE-2023-29175stated at publication 6.0.17, now states 6.0.18
2024-10-18Affected range extendedCVE-2023-28002stated at publication 6.0.17, now states 6.0.18
2025-11-18 to2026-01-14Affected range extendedstated at publication 7.0.17, now states 7.0.18
2026-01-14Affected range extendedCVE-2024-26008stated at publication 7.0.17, now states 7.0.18
2026-01-14Affected range extendedCVE-2025-57740stated at publication 7.0.17, now states 7.0.18
5 more rows in this change are not listed here. Open all 7 rows
2026-01-14Affected range extendedCVE-2024-46669stated at publication 7.2.10, now states 7.2.11
2025-11-03 to2025-11-18Affected range extendedstated at publication 7.2.11, now states 7.2.12
2025-11-18Affected range extendedCVE-2024-32122stated at publication 7.2.11, now states 7.2.12
2025-11-03Affected range extendedCVE-2025-24477stated at publication 7.2.11, now states 7.2.12
2025-11-18Affected range extendedCVE-2024-32122stated at publication 7.4.7, now states 7.4.8
2025-06-25Added to CISA KEVCVE-2019-6693listed by CISA 2025-06-25federal fix due 2025-07-16
2024-10-18Affected range extendedCVE-2023-28002stated at publication 6.2.15, now states 6.2.16
2024-10-18Affected range extendedCVE-2023-28002stated at publication 6.4.14, now states 6.4.15

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Fortinet and FortiOS changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.