
Fortinet
US network security vendor; recurring KEV presence and FortiBleed credential exposure affecting 194 countries in 2026.
CISA added three more actively-exploited flaws to its KEV catalogue between 24 July and 3 August 2026, including Fortinet's own FortiOS information-exposure flaw CVE-2025-68686, due for federal remediation by 10 August, the latest in a recurring pattern of Fortinet appliances reaching the mandatory-patch list.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How were 86,644 Fortinet credentials collected across 194 countries without a zero-day?
Timeline for Fortinet
Arista, Fortinet and Cisco flaws listed
Cybersecurity: Threats and DefencesMentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesCISA's KEV list runs a month late
Cybersecurity: Threats and DefencesMentioned in: A quiet KEV fortnight, then a 2008 bug
Cybersecurity: Threats and DefencesOne operator ran both ransomware brands
Cybersecurity: Threats and DefencesBackground
Fortinet is a US network security vendor, founded in 2000 and headquartered in Sunnyvale, California, providing firewalls, Secure Access Service Edge, endpoint security, and SD-WAN products to enterprises and government customers globally. It competes directly with Palo Alto Networks, Check Point, and Cisco in the enterprise network security market.
Its firewall and VPN products are widely deployed by government agencies, critical national infrastructure operators, and large enterprises, making them a high-value persistent target: an attacker who can enumerate credentials across Fortinet deployments in 194 countries holds a ready-made directory of network perimeters for future exploitation campaigns. For security teams, Fortinet's repeated KEV presence and the FortiBleed credential exposure both point to the same lesson, that credential hygiene and MFA enforcement across perimeter appliances now matter as much as patch cadence.
Its products keep reaching the KEV list
CISA added FortiOS information-exposure flaw CVE-2025-68686 to the Known Exploited Vulnerabilities catalogue between 24 July and 3 August 2026, with federal remediation due by 10 August, alongside an Arista command-injection flaw due 30 July and a Cisco hard-coded password flaw due 1 August.
The listing extends a pattern rather than breaking one. CISA had already added Fortinet's FortiSandbox malware-analysis appliance to the KEV catalogue on 16 July for CVE-2026-39808, an OS command-injection flaw CrowdSec had detected under active exploitation a full month earlier, on 17 June, and CVE-2026-21643, a SQL injection flaw, had reached the catalogue back in April. Repeated appearances across different product lines, FortiOS, FortiSandbox, and earlier FortiGate flaws, point to a company whose edge appliances stay a persistent federal-patch-list fixture rather than an occasional one.
Its leaked logins are now ransomware fuel
Researcher Volodymyr Diachenko's June 2026 discovery of 86,644 FortiGate firewall credentials spanning 194 countries, dubbed FortiBleed and built with no zero-day exploit, through credential reuse and traffic interception running since at least February, has since translated into real intrusions. Threat-intelligence firm SOCRadar linked the credential theft to ransomware group Lynx, which cracked the passwords using 45 chained graphics cards after Fortinet never modernised the old hashing method protecting the logins.
By 8 July, SOCRadar had confirmed the stolen credentials led to 12 ransomware deployments and 409 administrator-account compromises, with one operator running negotiation panels for two rival ransomware crews from the same stolen-access supply chain, showing how a single credential leak keeps generating intrusions for months after its initial disclosure.