FORTINET Security Advisory

Published Date: July 14, 2026

Advisory Summary

Fortinet has disclosed a significant vulnerability rated with a CVSSv3 score of 5.0 affecting multiple Fortinet products including FortiOS, FortiPAM, FortiProxy, and FortiSwitch Manager. This path traversal flaw (CWE-22) allows a privileged, authenticated attacker possessing physical access to the device to execute crafted CLI commands capable of deleting the device’s root file system. The potential for severe operational disruption and data loss is high, given the direct impact on the core file system.

This flaw underscores the ongoing need for robust physical security and vigilant privilege management in IT infrastructure environments, especially for critical network elements managed by Fortinet.

Reference: Vendor Advisory