logo

Fortinet FortiManager fgtupdates Flaw Enables Attackers to Execute Malicious Commands Remotely

ID: c31a5f4b-da47-5757-93b4-ee11f5248b87

STIX ID: report--c31a5f4b-da47-5757-93b4-ee11f5248b87

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-03-11

Date Updated: 2026-04-22

Author: Divya

...
...

Fortinet issued an advisory for CVE-2025-54820: a stack-based buffer overflow in the FortiManager `fgtupdates` service that can allow remote, unauthenticated command execution on affected versions (FortiManager 6.4 all; 7.2.0–7.2.10; 7.4.0–7.4.2). Fortinet recommends upgrading to fixed releases (7.4.3 or later, 7.2.11 or later) or temporarily disabling the `fgtupdates` service via CLI; FortiManager 7.6 and FortiManager Cloud are not affected and no active exploitation is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.