Skip to content
FortinetCVE-2025-53379

Fortinet FortiAuthenticator: out-of-bounds read

High7.5CVE-2025-53379 · Published Jul 14, 2026 · updated Jul 15, 2026

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

Fortinet advisory

Affected versions

PackageAffectedFixed in
FortiAuthenticator
Product
>= 6.6.0, <= 6.6.2No fix yet
>= 6.5.0, <= 6.5.7No fix yet
>= 6.4.0, <= 6.4.11No fix yet
>= 6.3.0, <= 6.3.5No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-125

More Fortinet advisories

All Fortinet
Advisory
Fortinet FortiOS: path traversal
Medium5.5Jul 14
Fortinet FortiOS: information disclosure
Medium4.3Jul 14
Fortinet FortiSIEMWindowsAgent: privilege escalation
High7.5Jul 14
Fortinet FortiSandbox: unauthenticated attacker could access the VNC server of...
High8.6Jul 14
Fortinet FortiClientEMS: improper certificate validation
High7.5Jul 14
Fortinet FortiOS: stack buffer overflow
Medium6.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.