Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Fortinet Security Updates – September 2026

Fortinet has released September 2026 security updates addressing multiple vulnerabilities across its products. One high‑severity vulnerability (CVE-2025-25249), confirmed to be activley exploited. The vulnerabilities may result in unauthorized access, system compromise, or disruption of services.
 
Affected Systems:
 
The affected systems and versions include, but are not limited to:
  • FortiOS: versions 7.6.0 – 7.6.7, 7.4.0 – 7.4.11, 7.2.0 – 7.2.11, 7.0.0 – 7.0.17
  • FortiSIEM: versions 7.5.0 – 7.5.1, 7.4.1 – 7.4.2,
  • FortiAnalyzer: versions 7.6.3 - 7.6.6.
  • FortiSOAR onpremise: versions 7.6.0 – 7.6.6, 7.5.0 –7.5.3, 7.4.0 – 7.4.5, 7.3.0 – 7.3.3
  • FortiSandbox on‑premise: versions 5.2.0, 5.0.0 – 5.0.6, 4.4.0 – 4.4.9
  • Fortiweb: versions 8.0.0 –  8.0.2, 7.6.0 – 7.6.5, 7.4.0 – 7.4.12, 7.2.0 – 7.2.13, 7.0.0 – 7.0.12
 
Security Risks
 
Successful exploitation of these vulnerabilities may allow unauthorized access, arbitrary command execution, privilege escalation, data exfiltration, or service disruption. For more information on the vulnerabilities addressed in this release, refer to the OpenCVE – Fortinet Vendor Feed.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) strongly recommends that system administrators:
 
1. Follow Fortinet Security Advisory to lower the risk of potential exploits, protect systems, and ensure their security.

 

2. Apply the required and latest security updates as soon as possible.
The released software versions for upgrade include, but are not limited to:
 
 
3. Before performing any update tasks, ensure that you have a backup of your data.

For further information and support, please contact NCSA by email at rwcsirt@ncsa.gov.rw or call us at 9009.

 
References

16 September 2026

© 2026 National Cyber Security Authority