CVE-2025-67604
Fortinet FortiManager vulnerability analysis and mitigation

Overview

CVE-2025-67604 is a Use of Potentially Dangerous Function (CWE-676) vulnerability in the API component of Fortinet FortiAnalyzer and FortiManager that allows an authenticated attacker to cause a system hang (denial of service) via multiple specially crafted HTTP requests. The vulnerability was internally discovered by Loic Pantano of Fortinet PSIRT and publicly disclosed on May 12, 2026. Affected versions include FortiAnalyzer and FortiManager 6.4 (all versions), 7.0 (all versions), 7.2 (all versions), 7.4.0–7.4.8, and 7.6.0–7.6.4; versions 8.0 and above are not affected. It carries a CVSS v3.1 base score of 5.2–5.3 (Medium) (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-676 (Use of Potentially Dangerous Function) and resides in the API signal handler of FortiAnalyzer and FortiManager. An authenticated attacker can send multiple specially crafted HTTP requests that trigger unsafe function usage within the API, causing crashes when internal locks happen to be aligned in a specific state. Because the lock alignment condition is non-deterministic and outside the attacker's direct control, exploitation requires repeated attempts to achieve the race condition. No public technical write-up or proof-of-concept code has been identified (FortiGuard Advisory).

Impact

Successful exploitation results in a system hang, rendering the FortiAnalyzer or FortiManager instance unavailable — a denial-of-service impact with no confidentiality or integrity consequences. Because FortiManager and FortiAnalyzer are central network management and log analysis platforms, their unavailability can disrupt security operations, policy management, and log visibility across the managed Fortinet infrastructure. There is no evidence of lateral movement capability or data exposure risk associated with this vulnerability (FortiGuard Advisory).

Exploitation steps

  1. Obtain authenticated access: Acquire valid low-privilege credentials for the FortiAnalyzer or FortiManager API (e.g., through credential theft, phishing, or insider access).
  2. Identify target version: Confirm the target is running a vulnerable version (FortiAnalyzer/FortiManager 6.4 all versions, 7.0 all versions, 7.2 all versions, 7.4.0–7.4.8, or 7.6.0–7.6.4).
  3. Craft malicious HTTP requests: Prepare multiple specially crafted HTTP requests targeting the vulnerable API endpoint to trigger unsafe function execution in the signal handler.
  4. Send repeated requests: Repeatedly send the crafted requests to the API, attempting to align internal locks in the required state — this is non-deterministic and may require many attempts.
  5. Achieve denial of service: If internal locks align during request processing, the system crashes and hangs, making the FortiAnalyzer or FortiManager instance unavailable (FortiGuard Advisory).

Indicators of compromise

  • Network: Unusually high volume of HTTP requests to the FortiAnalyzer or FortiManager API from a single authenticated source; repeated API calls in rapid succession that deviate from normal usage patterns.
  • Logs: API error logs showing repeated crashes or signal handler exceptions; system logs indicating unexpected process termination or restart events for the FortiAnalyzer/FortiManager service.
  • Process/System: Unexpected system hangs or unresponsive management interfaces; crash dump files generated by the FortiAnalyzer or FortiManager API process.

Mitigation and workarounds

Fortinet has released patched versions: FortiAnalyzer 7.6.5 or above, FortiAnalyzer 7.4.9 or above, FortiManager 7.6.5 or above, and FortiManager 7.4.9 or above. Users on FortiAnalyzer/FortiManager 7.2, 7.0, or 6.4 (all versions) should migrate to a fixed release as no in-branch patch is available. As interim mitigations, restrict API access to trusted networks and authorized users only, implement rate limiting on HTTP requests to the management interface, and monitor for anomalous API request patterns (FortiGuard Advisory).

Community reactions

Coverage of CVE-2025-67604 has been limited to routine security news aggregators and advisory republication sites, consistent with its medium severity rating. Outlets such as CyberSecurityNews and Cryptika covered it as part of Fortinet's May 2026 patch cycle alongside other vulnerabilities. No notable independent researcher commentary or significant social media discussion has been identified (CyberSecurityNews, Cryptika).

Additional resources


SourceThis report was generated using AI

Related Fortinet FortiManager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61848HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesApr 14, 2026
CVE-2026-22572HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026
CVE-2025-68649MEDIUM6.5
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortimanager
NoYesApr 14, 2026
CVE-2025-67604MEDIUM5.3
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMay 12, 2026
CVE-2026-22629LOW3.7
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management