CVEFinder.io

CVE-2026-22153

⚠️ high
🔍 Scan for this CVE
Summary

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

CVSS Score
8.1
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-02-10
First Seen: 2026-02-11
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 77.5% of all 326,604 vulnerabilities in our database.

#73,427
Top 25% most severe
Severity Percentile
Last Modified 2026-02-12
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-53844 ⚠️ high 8.8 0.0 A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 ... 2026-05-12
CVE-2025-53847 🔶 medium 6.5 0.0 A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro... 2026-04-14
CVE-2025-55018 🔶 medium 5.8 0.1 An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort... 2026-02-10
CVE-2025-64157 🔶 medium 6.7 0.0 A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug... 2026-02-10
CVE-2025-68686 🔶 medium 5.9 0.0 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS ... 2026-02-10
CVE-2026-24858 ⛔ critical 9.8 4.8 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnaly... 2026-01-27
These CVEs affect the same products