
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54820 is a stack-based buffer overflow vulnerability (CWE-121) in the fgtupdates service of Fortinet FortiManager that may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests when the service is enabled. It affects FortiManager 6.4 (all versions), 7.2.0 through 7.2.10, and 7.4.0 through 7.4.2; FortiManager 7.6 and FortiManager Cloud are not affected. The vulnerability was publicly disclosed on March 10, 2026, and was reported by catalpa from Dbappsecurity Co., Ltd. under responsible disclosure. It carries a CVSSv3.1 base score of 8.1 (High) per NVD, and 7.0 (High) per Fortinet's own advisory (FortiGuard Advisory).
The root cause is a stack-based buffer overflow (CWE-121 / CWE-787) in FortiManager's fgtupdates service, which fails to properly validate the size of attacker-controlled input before writing it to a stack buffer. An unauthenticated remote attacker can send specially crafted network requests to the exposed service to trigger the overflow and potentially overwrite return addresses or control flow data. Successful exploitation requires bypassing stack protection mechanisms (e.g., stack canaries, ASLR), which elevates the attack complexity to High. The vulnerability is only exploitable when the fgtupdates service is actively enabled on the FortiManager instance (FortiGuard Advisory).
Successful exploitation could allow a remote unauthenticated attacker to execute arbitrary commands on the affected FortiManager system, resulting in complete compromise of confidentiality, integrity, and availability. Since FortiManager is a centralized network management platform, a compromised instance could expose configuration data, credentials, and management access for all managed Fortinet devices, enabling significant lateral movement across enterprise networks (FortiGuard Advisory).
fgtupdates service.fgtupdates service is enabled on the target, as the vulnerability is only exploitable when this service is active.fgtupdates service handler, exceeding the expected input length.Fortinet has released patched versions addressing this vulnerability: upgrade FortiManager 7.4.x to 7.4.3 or above, and FortiManager 7.2.x to 7.2.11 or above. FortiManager 6.4 (all versions) is end-of-support for this fix and users should migrate to a fixed release. As an immediate workaround, if the fgtupdates service is active, it can be disabled via the CLI: config system interface → edit <interface> → set serviceaccess <services excluding fgtupdates> → end. Additionally, restrict network access to FortiManager management interfaces to trusted networks only (FortiGuard Advisory).
The vulnerability received coverage from multiple security news outlets including CyberSecurityNews, GBHackers, and CyberPress shortly after disclosure, highlighting the risk of remote unauthenticated command execution on a critical network management platform (CyberSecurityNews). Belgium's Centre for Cybersecurity (CCB) issued an advisory urging immediate patching as part of a broader Fortinet security update covering 22 vulnerabilities. Singapore's CSA also published an alert (AL-2026-024) referencing the vulnerability. Community discussion on LinkedIn and Bluesky noted the significance of the attack vector given FortiManager's role in enterprise network management.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."