CVE-2025-62439: exploitation status and patch state

CVE-2025-62439 · CVSS 4.2 MEDIUM · EPSS <1%

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

Is CVE-2025-62439 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2025-62439

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.