Assessment
Why it matters
The combination of confirmed exploitation, KEV inclusion, very high EPSS and an internet-facing edge product makes this an operational priority despite a CVSS score below 9.0.
Who should care
- Teams operating FortiGate appliances
- Organisations exposing administrative interfaces
- MSSPs responsible for perimeter infrastructure
Response plan
What I would do
- Confirm whether affected FortiOS versions exist in the environment.
- Check whether any management interface is reachable from untrusted networks.
- Apply the fixed release or vendor mitigation at emergency-change speed.
- Review appliance and identity logs for suspicious administrative activity.
- Rotate privileged credentials if compromise cannot be confidently excluded.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-78: OS Command Injection
- Affected versions
- Demonstration range: FortiOS 7.x before the fictional fixed releases
- Published
- 16 Aug 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- Vendor advisory published
- Exploitation evidence added
- KEV status confirmed
- Signal increased from 82 to 94