
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67604 is a Use of Potentially Dangerous Function (CWE-676) vulnerability in the API component of Fortinet FortiAnalyzer and FortiManager that allows an authenticated attacker to cause a system hang (denial of service) via multiple specially crafted HTTP requests. The vulnerability was internally discovered by Loic Pantano of Fortinet PSIRT and publicly disclosed on May 12, 2026. Affected versions include FortiAnalyzer and FortiManager 6.4 (all versions), 7.0 (all versions), 7.2 (all versions), 7.4.0–7.4.8, and 7.6.0–7.6.4; versions 8.0 and above are not affected. It carries a CVSS v3.1 base score of 5.2–5.3 (Medium) (FortiGuard Advisory).
The vulnerability is classified as CWE-676 (Use of Potentially Dangerous Function) and resides in the API signal handler of FortiAnalyzer and FortiManager. An authenticated attacker can send multiple specially crafted HTTP requests that trigger unsafe function usage within the API, causing crashes when internal locks happen to be aligned in a specific state. Because the lock alignment condition is non-deterministic and outside the attacker's direct control, exploitation requires repeated attempts to achieve the race condition. No public technical write-up or proof-of-concept code has been identified (FortiGuard Advisory).
Successful exploitation results in a system hang, rendering the FortiAnalyzer or FortiManager instance unavailable — a denial-of-service impact with no confidentiality or integrity consequences. Because FortiManager and FortiAnalyzer are central network management and log analysis platforms, their unavailability can disrupt security operations, policy management, and log visibility across the managed Fortinet infrastructure. There is no evidence of lateral movement capability or data exposure risk associated with this vulnerability (FortiGuard Advisory).
Fortinet has released patched versions: FortiAnalyzer 7.6.5 or above, FortiAnalyzer 7.4.9 or above, FortiManager 7.6.5 or above, and FortiManager 7.4.9 or above. Users on FortiAnalyzer/FortiManager 7.2, 7.0, or 6.4 (all versions) should migrate to a fixed release as no in-branch patch is available. As interim mitigations, restrict API access to trusted networks and authorized users only, implement rate limiting on HTTP requests to the management interface, and monitor for anomalous API request patterns (FortiGuard Advisory).
Coverage of CVE-2025-67604 has been limited to routine security news aggregators and advisory republication sites, consistent with its medium severity rating. Outlets such as CyberSecurityNews and Cryptika covered it as part of Fortinet's May 2026 patch cycle alongside other vulnerabilities. No notable independent researcher commentary or significant social media discussion has been identified (CyberSecurityNews, Cryptika).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."