4
Published signals
currently linked to this company
Company intelligence
fortinet.com
Fortinet is a cybersecurity company providing network, cloud, endpoint and security-operations products through its Security Fabric platform.
4
currently linked to this company
1
recent published signals
2
recent published signals
3
confidence classifications
July 2, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Fortinet. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.
A Russian-speaking cybercriminal group exposed credentials for approximately 74,000 to 86,644 Fortinet FortiGate firewalls and VPN gateways across 194 countries. The incident, dubbed 'FortiBleed', involved leaked administrative and SSL VPN credentials, prompting CISA to issue a hardening alert. The exposure was publicly reported on June 22, 2026, following discovery on June 13, 2026.
Threat actors are actively exploiting critical vulnerabilities in Fortinet FortiClient Endpoint Management Server (EMS), including CVE-2026-35616 and CVE-2026-21643. CVE-2026-35616, a critical security flaw, was actively exploited in the wild to deploy credential-stealing malware (EKZ Infostealer), prompting an emergency patch in April 2026. CVE-2026-21643 is also mentioned in active exploitation campaigns.
Multiple critical authentication bypass vulnerabilities related to FortiCloud Single Sign-On (SSO) have been actively exploited in Fortinet products. CVE-2026-24858, disclosed in January 2026, allowed malicious actors with a FortiCloud account to log in to devices registered to other users if FortiCloud SSO was enabled. This led to unauthorized firewall configuration changes, account creation, and VPN configuration changes. Earlier, CVE-2025-59718 and CVE-2025-59719 (December 2025) allowed unauthenticated attackers to bypass SSO login via crafted SAML messages. Attacks exploiting these flaws have been observed creating rogue accounts and stealing firewall configuration data.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Fortinet.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.