Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customersCyberScoop·Jan 29, 04:52 UTC · Jan 29, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last WeekThe Hacker News·Jun 19, 13:44 UTC · Jun 19, 2026Vulnerability in the wildCVE-2026-39813CVE-2026-39808CVE-2026-25089+1 CVEs60
Fortinet SIEM issue coincides with spike in bruteCyberScoop·Aug 13, 19:21 UTC · Aug 13, 2025Ransomware in the wildCVE-2025-25256CVE-2023-48788CVE-2024-4757560
CISA adds Fortinet bug to exploited vulnerabilities listThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Vulnerability in the wildCVE-2022-40684CVE-2018-1337960
Fortinet’s delayed alert on actively exploited defect put defenders at a disadvantageCyberScoop·Nov 17, 21:01 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-6444660
Brute-force attacks hammer Fortinet devices worldwideHelp Net Security·Aug 14, 00:00 UTC · Aug 14, 2025Exploit / PoC in the wild60
Fortinet Confirms Exploitation of Critical FortiManager ZeroInfosecurity Magazine·Oct 24, 11:45 UTC · Oct 24, 2024Exploit / PoC in the wildCVE-2024-47575CVE-2024-2311360
CVE-2026-35616: Fortinet fixes actively exploited highSecurity Affairs·Apr 6, 13:07 UTC · Apr 6, 2026Vulnerability in the wildCVE-2026-35616CVE-2026-2164360
Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026Security Affairs·Jan 28, 15:58 UTC · Jan 28, 2026Vulnerability in the wildCVE-2026-24858CVE-2025-59718CVE-2025-5971960
Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858)Help Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
Threat actors are offering access to corporate networks via unauthorized Fortinet VPN accessSecurity Affairs·Nov 29, 22:22 UTC · Nov 29, 2022Threat actor in the wildCVE-2022-4068460
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
Fortinet FortiWeb flaw CVE-2025Security Affairs·Jul 19, 16:25 UTC · Jul 19, 2025Exploit / PoC in the wildCVE-2025-2525760
Fortinet Warns of Critical Vulnerability in FortiManager Under Active ExploitationThe Hacker News·Nov 15, 04:35 UTC · Nov 15, 2024Vulnerability in the wildCVE-2024-4757560
Fortinet warns of active campaign exploiting bug in FortiManager productsCyberScoop·Oct 24, 21:22 UTC · Oct 24, 2024Threat actor in the wildCVE-2024-4757560
Hackers Leverage Compromised Fortinet Devices to Distribute RansomwareInfosecurity Magazine·Jan 5, 18:00 UTC · Jan 5, 2023Ransomware in the wildCVE-2022-4068460
Fortinet settles charges of selling intentionally mislabeled ChineseCyberScoop·Apr 16, 14:02 UTC · Apr 16, 2019Exploit / PoC in the wild60
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilCyberScoop·Jun 18, 14:32 UTC · Jun 18, 2026Vulnerability in the wildCVE-2026-39808CVE-2026-39813CVE-2026-2508960
FortiBleed Exposes Admin Passwords for 75,000 Fortinet FirewallsSecurity Affairs·Jun 18, 07:31 UTC · Jun 18, 2026Exploit / PoC in the wild60
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
CISA gives federal agencies one week to patch exploited Fortinet bugThe Record·Nov 17, 13:33 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-64446160
Fortinet Patches Critical Bug in FortiClient EMSInfosecurity Magazine·Mar 14, 10:15 UTC · Mar 14, 2024Vulnerability in the wildCVE-2023-48788CVE-2023-42789CVE-2023-42790+2 CVEs60
CISA Warns of Active Exploitation Following FortiBleed LeakSecurity Affairs·Jun 20, 08:27 UTC · Jun 20, 2026Advisory in the wild60
Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718?Help Net Security·Jan 27, 23:23 UTC · Jan 27, 2026Vulnerability in the wildCVE-2025-59718CVE-2025-5971960
CISA Mandates Urgent Patch for Actively Exploited Fortinet FlawsInfosecurity Magazine·Jul 17, 09:45 UTC · Jul 17, 2026Vulnerability in the wildCVE-2026-39808CVE-2026-2508960
Fortinet customers confront actively exploited zeroCyberScoop·Apr 6, 21:12 UTC · Apr 6, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-2164360
Critical Fortinet FortiClient EMS flaw exploited for Remote Code ExecutionSecurity Affairs·Mar 30, 10:44 UTC · Mar 30, 2026Vulnerability in the wildCVE-2026-21643CVE-2023-4878860
U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 13:48 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
Fortinet fixed a critical RCE bug in FortiClientLinuxSecurity Affairs·Apr 10, 18:15 UTC · Apr 10, 2024Vulnerability in the wildCVE-2023-4559060
Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after release of PoC exploitSecurity Affairs·Feb 23, 19:45 UTC · Feb 23, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-4275660
Fortinet plugs critical security hole in FortiNAC, with a PoC incoming (CVE-2022-39952)Help Net Security·Feb 20, 00:00 UTC · Feb 20, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-42756CVE-2022-4247560
U.S. CISA adds a flaw in Fortinet FortiClient EMS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 7, 09:02 UTC · Apr 7, 2026Exploit / PoC in the wildCVE-2026-3561660
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation DetectedThe Hacker News·Jan 29, 06:05 UTC · Jan 29, 2026Vulnerability in the wildCVE-2026-2485860
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass VulnerabilityThe Hacker News·Jan 3, 08:24 UTC · Jan 3, 2026Vulnerability in the wildCVE-2020-1281260
Five-year-old Fortinet FortiOS SSL VPN flaw actively exploitedSecurity Affairs·Dec 25, 19:40 UTC · Dec 25, 2025Ransomware in the wildCVE-2020-12812CVE-2018-13379CVE-2019-559160
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 17, 08:17 UTC · Dec 17, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-5971960
A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warnHelp Net Security·Nov 16, 15:28 UTC · Nov 16, 2025Exploit / PoC in the wildCVE-2025-6444660
U.S. CISA adds a Fortinet flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 15, 09:07 UTC · May 15, 2025Exploit / PoC in the wildCVE-2025-3275660
New Fortinet and Ivanti Zero Days Exploited in the WildInfosecurity Magazine·May 14, 13:00 UTC · May 14, 2025Exploit / PoC in the wildCVE-2025-32756CVE-2025-4427CVE-2025-442860
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160