Cyber Posture

CVE-2026-22153

High

Published: 10 February 2026

Published
10 February 2026
Modified
12 February 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0008 22.9th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-22153 is a high-severity Authentication Bypass by Primary Weakness (CWE-305) vulnerability in Fortinet Fortios. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 22.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-2 (Flaw Remediation) and AC-17 (Remote Access).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190) and 1 other technique. What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Mandates timely identification, reporting, and remediation of system flaws, directly addressing this FortiOS LDAP authentication bypass by requiring patching of affected versions.

prevent

Requires robust identification and authentication for organizational users, mitigating authentication bypass risks in LDAP for Agentless VPN and FSSO though not fixing the specific software flaw.

AC-17 Remote Access partial match
prevent

Establishes authorization and restrictions for remote access including Agentless VPN, limiting exploitation of the LDAP authentication bypass to unauthorized network access.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1133 External Remote Services Persistence
Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
Why these techniques?

Auth bypass vuln in public-facing FortiOS VPN/FSSO service directly enables remote exploitation for unauthorized access (T1190) and abuse of external remote services (T1133).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific…

more

way.

Deeper analysisAI

CVE-2026-22153 is an Authentication Bypass by Primary Weakness vulnerability (CWE-305) in Fortinet FortiOS versions 7.6.0 through 7.6.4. The issue affects LDAP authentication for Agentless VPN or FSSO policy when the remote LDAP server is configured in a specific way, potentially allowing unauthenticated attackers to bypass authentication controls. It carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity with network accessibility but high attack complexity.

An unauthenticated attacker can exploit this vulnerability over the network without privileges or user interaction, provided the required specific LDAP server configuration exists. Successful exploitation bypasses LDAP authentication, enabling unauthorized access to Agentless VPN or FSSO policies and resulting in high impacts to confidentiality, integrity, and availability.

Mitigation details are available in the Fortinet PSIRT advisory at https://fortiguard.fortinet.com/psirt/FG-IR-25-1052.

Details

CWE(s)

Affected Products

fortinet
fortios
7.6.0 — 7.6.5

CVEs Like This One

CVE-2025-53847Same product: Fortinet Fortios
CVE-2025-64157Same product: Fortinet Fortios
CVE-2024-40591Same product: Fortinet Fortios
CVE-2024-46668Same product: Fortinet Fortios
CVE-2024-46670Same product: Fortinet Fortios
CVE-2024-35279Same product: Fortinet Fortios
CVE-2025-24472Same product: Fortinet Fortios
CVE-2024-55591Same product: Fortinet Fortios
CVE-2024-26006Same product: Fortinet Fortios
CVE-2025-25249Same product: Fortinet Fortios

References