An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
https://www.securityweek.com/ivanti-fortinet-patch-remote-code-execution-vulnerabilities/
https://thehackernews.com/2025/02/ivanti-patches-critical-flaws-in.html