Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3034 articles · 183090 vulns · 36/41 feeds (7d)
← Back to list
7.0
CVE-2025-53379EXPLOITED
fortinet · fortiauthenticator

CVE-2025-53379: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio

Description

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

Affected Products

VendorProductVersions
fortinetfortiauthenticator6.6.0, 6.5.0, 6.4.0, 6.3.0

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-146

Related News (3 articles)

Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Fortinet (15 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada17d ago
Fortinet security advisory (AV26-695)
→ No new info (linked only)
Tier C
VulDB18d ago
CVE-2025-53379 | Fortinet FortiAuthenticator up to 6.3.5/6.4.11/6.5.7/6.6.2 out-of-bounds
→ No new info (linked only)
CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-125
PublishedJul 14, 2026
Last enriched17d agov3
Trending Score6
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 83
HIGHCVE-2026-59835
CVE-2026-59835: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Trending: 9
MEDIUMCVE-2026-59837
CVE-2026-59837: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM
Trending: 7
MEDIUMCVE-2026-23573
CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi
Trending: 6
MEDIUMCVE-2026-59839
CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Trending: 6

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Updated: affectedVersions, exploitAvailable, activelyExploited
Jul 14, 2026
Actively Exploited
Jul 22, 2026
Exploit Available
Jul 22, 2026

Version History

v3
Last enriched 17d ago
v3Tier B17d ago

Updated affected versions to include 6.5.1 through 6.5.7 and marked the vulnerability as actively exploited with an exploit available.

affectedVersionsexploitAvailableactivelyExploited
via CCCS Canada
v2Tier C18d ago

Updated affected versions to include 6.3.5, 6.4.11, and 6.5.7, and corrected exploit availability to false.

affectedVersions
via VulDB
v118d ago

Initial creation