
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62439 is an Improper Verification of Source of a Communication Channel vulnerability (CWE-940) in Fortinet FortiOS affecting the FSSO (Fortinet Single Sign-On) Terminal Services Agent. It allows an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests. Affected versions include FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 (all versions), and FortiOS 7.0 (all versions); FortiOS 6.4 and 8.0 are not affected. The vulnerability was publicly disclosed on February 10, 2026, and carries a CVSSv3 base score of 3.8–4.2 (Low/Medium) (FortiGuard Advisory).
The root cause is classified as CWE-940 (Improper Verification of Source of a Communication Channel), meaning FortiOS does not adequately verify the origin of communications within the FSSO Terminal Services Agent component. An authenticated attacker who has knowledge of FSSO policy configurations can craft malicious requests that exploit this trust relationship, effectively bypassing firewall policy controls enforced by the FSSO TS Agent. The attack vector is local, requires low privileges, and has high complexity, with no user interaction needed; the scope is changed, indicating impact can extend beyond the vulnerable component (FortiGuard Advisory). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation allows an authenticated, low-privileged attacker to bypass FSSO-enforced firewall policies and gain unauthorized access to protected network resources that would otherwise be restricted. The impact includes limited confidentiality and integrity compromise (both rated Low), with no availability impact. Because the scope is changed, the attacker may be able to access resources across security boundaries beyond the initially compromised system, posing a risk of lateral movement within segmented network environments (FortiGuard Advisory).
There is no known active exploitation of CVE-2025-62439 in the wild, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Fortinet has confirmed the vulnerability was discovered externally and reported under responsible disclosure by Tijl Deneut from e-BO Enterprises. The EPSS score is very low at approximately 0.015%, reflecting minimal current exploitation probability. No exploit kits or weaponized code have been publicly identified (FortiGuard Advisory).
Fortinet recommends upgrading FortiOS 7.6.x to version 7.6.5 or above, paired with FSSO TS Agent version 5.0 build 0324 or later. For FortiOS 7.4.x, upgrade to the upcoming 7.4.10 or above with the same FSSO TS Agent version. Users running FortiOS 7.2 or 7.0 (all versions) should migrate to a fixed release, as no patch is planned for those branches. Upgrading the FSSO TS Agent to version 5.0 build 0324 or later is a required component of the fix alongside the FortiOS upgrade. Fortinet's upgrade path tool is available at https://docs.fortinet.com/upgrade-tool (FortiGuard Advisory).
The CIS (Center for Internet Security) included this vulnerability in a broader advisory covering multiple Fortinet product vulnerabilities, noting the potential for unauthorized access (CIS Advisory). Belgium's Centre for Cybersecurity (CCB) also issued a warning advising organizations to patch Fortinet products promptly (CCB Advisory). The vulnerability was reported responsibly by Tijl Deneut from e-BO Enterprises, and Fortinet acknowledged the disclosure in its advisory (FortiGuard Advisory). Overall community reaction has been measured given the low severity rating and authentication requirement.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."