Authentication Bypass in Fortinet FortiOS, FortiProxy, and FortiPAM
CVE-2024-26009
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 12 August 2025
What is CVE-2024-26009?
An authentication bypass vulnerability exists in Fortinet's FortiOS, FortiProxy, and FortiPAM products, allowing unauthenticated attackers to potentially gain control of managed devices. This vulnerability arises when crafted FGFM requests are sent to devices managed by FortiManager, particularly if the attacker has the FortiManager’s serial number. The issue affects specific versions of FortiOS, FortiProxy, and FortiPAM. It is crucial for organizations to review their systems and apply necessary security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiOS 6.4.0 <= 6.4.15
FortiOS 6.2.0 <= 6.2.16
FortiOS 6.0.0 <= 6.0.18
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved