CVE-2025-68648
Fortinet FortiManager vulnerability analysis and mitigation

Overview

CVE-2025-68648 is a use of externally-controlled format string vulnerability (CWE-134) in the fazsvcd daemon of Fortinet FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud. It affects FortiAnalyzer and FortiManager versions 7.0 (all), 7.2 (all), 7.4.0–7.4.7, and 7.6.0–7.6.4, along with their respective Cloud variants. The vulnerability was internally discovered by David Maciejak of Fortinet's Product Security team and publicly disclosed on March 10, 2026. It carries a CVSS v3.1 base score of 7.2 (High) per NVD, or 6.5 (Medium) per Fortinet's own advisory scoring (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-134 (Use of Externally-Controlled Format String) and resides in the fazsvcd daemon component, accessible via the API. An attacker who has already obtained a remote privileged account with an admin profile can send specially crafted requests that inject format string specifiers, causing the daemon to interpret attacker-controlled data as format strings. This can lead to arbitrary code or command execution on the affected system. Exploitation requires network access and authenticated high-privilege credentials, limiting the attack surface but not eliminating risk in environments with compromised admin accounts (FortiGuard Advisory).

Impact

Successful exploitation allows a remote privileged attacker to escalate privileges and execute arbitrary code or commands on affected FortiAnalyzer and FortiManager instances. Given that these products serve as centralized network management and logging platforms, compromise could expose sensitive network telemetry, device configurations, and credentials across the managed infrastructure. The high confidentiality, integrity, and availability impact scores reflect the potential for full system compromise and lateral movement to managed network devices (FortiGuard Advisory).

Exploitation steps

  1. Obtain Admin Credentials: Acquire valid administrative credentials for a target FortiAnalyzer or FortiManager instance (e.g., through credential theft, phishing, or reuse of compromised credentials).
  2. Identify Vulnerable Version: Confirm the target is running a vulnerable version (FortiAnalyzer/FortiManager 7.0.x, 7.2.x, 7.4.0–7.4.7, or 7.6.0–7.6.4) via the management interface or API version disclosure.
  3. Craft Malicious API Request: Construct a specially crafted API request targeting the fazsvcd daemon that includes format string specifiers (e.g., %n, %x, %s) in a parameter that is passed unsanitized to a format string function.
  4. Send Request: Submit the crafted request to the FortiAnalyzer/FortiManager API endpoint using the authenticated admin session.
  5. Achieve Code Execution: The fazsvcd daemon processes the format string, allowing the attacker to read memory, overwrite memory locations, or execute arbitrary commands with elevated privileges on the host system (FortiGuard Advisory).

Mitigation and workarounds

Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following fixed releases:

  • FortiAnalyzer / FortiManager: 7.4.8 or above (for 7.4.x), 7.6.5 or above (for 7.6.x)
  • FortiAnalyzer Cloud / FortiManager Cloud: 7.4.8 or above (for 7.4.x), 7.6.5 or above (for 7.6.x)
  • FortiAnalyzer / FortiManager 7.0 and 7.2 (all versions): Migrate to a fixed release, as no patch is available for these branches.

No specific configuration-based workaround is provided by Fortinet. As a general hardening measure, restrict administrative access to FortiAnalyzer and FortiManager to trusted IP ranges and enforce multi-factor authentication on admin accounts (FortiGuard Advisory).

Community reactions

The vulnerability was covered by cybersecurity news outlets as part of Fortinet's March 2026 security update batch. Coverage noted the format string flaw alongside other vulnerabilities patched in the same release cycle (Cybersecurity News). No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Fortinet FortiManager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61848HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesApr 14, 2026
CVE-2026-22572HIGH7.2
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026
CVE-2025-68649MEDIUM6.5
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortimanager
NoYesApr 14, 2026
CVE-2025-67604MEDIUM5.3
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMay 12, 2026
CVE-2026-22629LOW3.7
  • Fortinet FortiManager logoFortinet FortiManager
  • cpe:2.3:a:fortinet:fortianalyzer
NoYesMar 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management