Skip to main content

Company intelligence

Fortinet cybersecurity incidents and threat signals

fortinet.com

Fortinet logo

Fortinet is a cybersecurity company providing network, cloud, endpoint and security-operations products through its Security Fabric platform.

Company country

United States

Facts last verified July 23, 2026

4

Published signals

currently linked to this company

1

Last 28 days

recent published signals

2

Last 90 days

recent published signals

3

High or critical

confidence classifications

July 2, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Fortinet. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Fortinet

Fortinet logoRansomware
High

FortiBleed gekoppeld aan ransomwaregroepen INC en Lynx

The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.

Fortinet
Fortinet logo
Medium

Fortinet FortiBleed Credential Exposure Affects Tens of Thousands of Devices

A Russian-speaking cybercriminal group exposed credentials for approximately 74,000 to 86,644 Fortinet FortiGate firewalls and VPN gateways across 194 countries. The incident, dubbed 'FortiBleed', involved leaked administrative and SSL VPN credentials, prompting CISA to issue a hardening alert. The exposure was publicly reported on June 22, 2026, following discovery on June 13, 2026.

Fortinet
Fortinet logoInfostealer
High

Critical FortiClient EMS Flaws Actively Exploited to Deploy Credential Stealers

Threat actors are actively exploiting critical vulnerabilities in Fortinet FortiClient Endpoint Management Server (EMS), including CVE-2026-35616 and CVE-2026-21643. CVE-2026-35616, a critical security flaw, was actively exploited in the wild to deploy credential-stealing malware (EKZ Infostealer), prompting an emergency patch in April 2026. CVE-2026-21643 is also mentioned in active exploitation campaigns.

Fortinet
Fortinet logo
High

FortiCloud SSO Authentication Bypass Vulnerabilities Actively Exploited

Multiple critical authentication bypass vulnerabilities related to FortiCloud Single Sign-On (SSO) have been actively exploited in Fortinet products. CVE-2026-24858, disclosed in January 2026, allowed malicious actors with a FortiCloud account to log in to devices registered to other users if FortiCloud SSO was enabled. This led to unauthorized firewall configuration changes, account creation, and VPN configuration changes. Earlier, CVE-2025-59718 and CVE-2025-59719 (December 2025) allowed unauthenticated attackers to bypass SSO login via crafted SAML messages. Attacks exploiting these flaws have been observed creating rogue accounts and stealing firewall configuration data.

Fortinet

FAQ

Questions about Fortinet cybersecurity reporting

What does the Fortinet page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Fortinet.

Does every mention of Fortinet appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.