LDAP Credential Decryption Vulnerability in Fortinet FortiOS
CVE-2026-25815
What is CVE-2026-25815?
Fortinet FortiOS versions up to 7.6.6 are susceptible to a vulnerability that allows unauthorized entities to decrypt LDAP credentials stored within device configuration files. This security flaw has been actively exploited since December 16, 2025, due to the consistent use of a single encryption key across all installations. Although Fortinet asserts that customers are meant to activate a non-default encryption option that mitigates this issue, enabling such an option can disrupt system functionality as highlighted in the management guidelines for FortiGates. This indicates that many users may remain exposed if they do not adjust their settings accordingly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiOS 0 <= 7.6.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved