Skip to content
You can now search across every topic, entity and event.What's new
Fortinet
OrganisationUS

Fortinet

US network security vendor; recurring KEV presence and FortiBleed credential exposure affecting 194 countries in 2026.

CISA added three more actively-exploited flaws to its KEV catalogue between 24 July and 3 August 2026, including Fortinet's own FortiOS information-exposure flaw CVE-2025-68686, due for federal remediation by 10 August, the latest in a recurring pattern of Fortinet appliances reaching the mandatory-patch list.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

How were 86,644 Fortinet credentials collected across 194 countries without a zero-day?

Timeline for Fortinet

#12 28 Jul

Arista, Fortinet and Cisco flaws listed

Cybersecurity: Threats and Defences
#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#11 16 Jul

CISA's KEV list runs a month late

Cybersecurity: Threats and Defences
#10 14 Jul

Mentioned in: A quiet KEV fortnight, then a 2008 bug

Cybersecurity: Threats and Defences
#10 8 Jul

One operator ran both ransomware brands

Cybersecurity: Threats and Defences
View full timeline →

Background

Fortinet is a US network security vendor, founded in 2000 and headquartered in Sunnyvale, California, providing firewalls, Secure Access Service Edge, endpoint security, and SD-WAN products to enterprises and government customers globally. It competes directly with Palo Alto Networks, Check Point, and Cisco in the enterprise network security market.

Its firewall and VPN products are widely deployed by government agencies, critical national infrastructure operators, and large enterprises, making them a high-value persistent target: an attacker who can enumerate credentials across Fortinet deployments in 194 countries holds a ready-made directory of network perimeters for future exploitation campaigns. For security teams, Fortinet's repeated KEV presence and the FortiBleed credential exposure both point to the same lesson, that credential hygiene and MFA enforcement across perimeter appliances now matter as much as patch cadence.

Key Issues
Recurring KEV presence

Its products keep reaching the KEV list

CISA added FortiOS information-exposure flaw CVE-2025-68686 to the Known Exploited Vulnerabilities catalogue between 24 July and 3 August 2026, with federal remediation due by 10 August, alongside an Arista command-injection flaw due 30 July and a Cisco hard-coded password flaw due 1 August.

The listing extends a pattern rather than breaking one. CISA had already added Fortinet's FortiSandbox malware-analysis appliance to the KEV catalogue on 16 July for CVE-2026-39808, an OS command-injection flaw CrowdSec had detected under active exploitation a full month earlier, on 17 June, and CVE-2026-21643, a SQL injection flaw, had reached the catalogue back in April. Repeated appearances across different product lines, FortiOS, FortiSandbox, and earlier FortiGate flaws, point to a company whose edge appliances stay a persistent federal-patch-list fixture rather than an occasional one.

FortiBleed fallout

Its leaked logins are now ransomware fuel

Researcher Volodymyr Diachenko's June 2026 discovery of 86,644 FortiGate firewall credentials spanning 194 countries, dubbed FortiBleed and built with no zero-day exploit, through credential reuse and traffic interception running since at least February, has since translated into real intrusions. Threat-intelligence firm SOCRadar linked the credential theft to ransomware group Lynx, which cracked the passwords using 45 chained graphics cards after Fortinet never modernised the old hashing method protecting the logins.

By 8 July, SOCRadar had confirmed the stolen credentials led to 12 ransomware deployments and 409 administrator-account compromises, with one operator running negotiation panels for two rival ransomware crews from the same stolen-access supply chain, showing how a single credential leak keeps generating intrusions for months after its initial disclosure.

Common Questions
What is the Fortinet vulnerability CISA added to KEV in 2026?
CISA added CVE-2026-21643, a SQL injection vulnerability in Fortinet's network security products, to the Known Exploited Vulnerabilities catalogue in April 2026 as actively exploited.Source: CISA KEV
What is FortiBleed and does it affect my Fortinet firewall?
FortiBleed is a credential database of 86,644 Fortinet FortiGate logins spanning 194 countries, collected via credential reuse and traffic interception since at least February 2026 without any zero-day exploit. NCSC and CISA issued joint alerts on 18 June 2026 advising organisations to rotate credentials and enforce MFA on Fortinet devices.Source: NCSC / CISA joint alert, June 2026
Why does Fortinet keep appearing in CISA's KEV catalogue?
Fortinet's widely-deployed firewall and VPN products are high-value persistent targets for state and criminal actors. CISA has added multiple Fortinet CVEs to the KEV catalogue in successive years, including FortiOS vulnerabilities exploited by Chinese state-linked groups and CVE-2026-21643 (SQL injection) in April 2026, because confirmed exploitation in the wild meets the KEV threshold.Source: CISA KEV
What should Fortinet customers do after the FortiBleed credential leak?
NCSC and CISA recommend rotating all Fortinet FortiGate credentials, enforcing multi-factor authentication on management interfaces, auditing VPN access logs for anomalous sessions, and reviewing CISA's June 2026 advisory for indicators of compromise.Source: NCSC / CISA joint alert, June 2026
How was the FortiBleed database built without exploiting a vulnerability?
The FortiBleed dataset was assembled via credential reuse from prior breaches and traffic interception at network level, not via any zero-day or unpatched CVE. It had been running since at least February 2026. This means that patched Fortinet devices with reused or weak credentials were still captured.Source: NCSC / CISA joint alert, June 2026
What is the FortiSandbox vulnerability CISA added to KEV in July 2026?
CVE-2026-39808 is an OS command-injection flaw in Fortinet's FortiSandbox appliance. CrowdSec detected it under active exploitation on 17 June 2026, but CISA did not ADD it to the KEV catalogue until 16 July, a one-month gap.Source: CrowdSec
Source Material