CVE-2025-68482Disclosure(fortinet / fortianalyzer)

LOWCVSS 5.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to view confidential information via a man in the middle [MiTM] attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortianalyzer
  • fortimanager

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-17)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fortianalyzerfortimanager

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-13: 1Mentions · 2026-03-17: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 203-1303-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-172
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2025-68482 A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, Fort… https://www.cve.org/CVERecord?id=CVE-2025-68482 ----- Traducción: CVE-2025-68482 Una… http://infoflow.cloud`

    Post summary

    CVE‑2025‑68482 is described as an improper certificate validation vulnerability affecting multiple FortiAnalyzer versions; the post supplies basic vulnerability details but no exploitation or remediation information.

    00000107
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-68482 A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, Fort… https://www.cve.org/CVERecord?id=CVE-2025-68482

    Post summary

    The text announces the existence of CVE-2025-68482, detailing the affected FortiAnalyzer versions, but provides no exploit, patch, or PoC information.

    00000260
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 FortiAnalyzer & FortiManager Improper Certificate Validation, #CVE-2025-68482 (Medium) https://dailycve.com/fortianalyzer-fortimanager-improper-certificate-validation-cve-2025-68482-medium/

    Post summary

    The post lists a Medium‑severity CVE for FortiAnalyzer & FortiManager involving improper certificate validation and provides a link to a DailyCVE article, without indicating any PoC, exploit, active exploitation, or patch.

    0000098
    168 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortianalyzer---
Appfortinetfortimanager---

Explore more