Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3018 articles · 157069 vulns · 36/41 feeds (7d)
← Back to list
6.3
CVE-2025-53681
Fortinet · FortiMail

CVE-2025-53681: An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab

Description

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

Affected Products

VendorProductVersions
FortinetFortiMail7.6.0, 7.4.0, 7.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortimailcert_advisory90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-132

Related News (4 articles)

Tier B
BSI Advisories15d ago
[NEU] [mittel] Fortinet FortiMail: Schwachstelle ermöglicht SQL Injection
→ No new info (linked only)
Tier B
CERT-FR15d ago
Multiples vulnérabilités dans les produits Fortinet (13 mai 2026)
→ No new info (linked only)
Tier C
VulDB15d ago
CVE-2025-53681 | Fortinet FortiMail up to 7.2.8/7.4.5/7.6.3 HTTP sql injection (FG-IR-26-132)
→ No new info (linked only)
Tier A
Fortinet PSIRT16d ago
SQL command injection in administrative portal
→ No new info (linked only)
CVSS 3.16.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
CWECWE-89
PublishedMay 12, 2026
Last enriched15d ago
Trending Score9
Source articles4
Independent4
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-35616EXPKEV
CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
Trending: 170
CRITICALCVE-2026-26083
CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo
Trending: 15
CRITICALCVE-2026-44277EXP
CVE-2026-44277: A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat
Trending: 12
HIGHCVE-2025-53844EXP
CVE-2025-53844: A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0
Trending: 9
MEDIUMCVE-2025-53870EXP
CVE-2025-53870: An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
Trending: 8

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 12, 2026
Discovered by ZDM
May 12, 2026