U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 5, 15:24 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2025-68686CVE-2026-1681260
FBI and CISA are warning of APT actors targeting Fortinet FortiOS serversSecurity Affairs·Apr 2, 21:19 UTC · Apr 2, 2021VulnerabilityCVE-2018-13379CVE-2020-12812CVE-2019-5591+1 CVEs60
Multiple flaws in Fortinet FortiOS fixedSecurity Affairs·Jun 13, 08:31 UTC · Jun 13, 2024Exploit / PoC in the wildCVE-2024-23110CVE-2024-26010CVE-2024-23111+2 CVEs60
Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warnsSecurity Affairs·Sep 8, 12:06 UTC · Sep 8, 2023Threat actor in the wildCVE-2022-47966CVE-2022-42475CVE-2021-4422860
U.S. CISA adds AMI MegaRAC SPx, D-Link DIR-859 routers, and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 26, 08:15 UTC · Jun 26, 2025Exploit / PoC in the wildCVE-2024-54085CVE-2024-0769CVE-2019-669360
Five-year-old Fortinet FortiOS SSL VPN flaw actively exploitedSecurity Affairs·Dec 25, 19:40 UTC · Dec 25, 2025Ransomware in the wildCVE-2020-12812CVE-2018-13379CVE-2019-559160
Critical Fortinet FortiOS bug CVE-2024-21762 potentially impact 150,000 internetSecurity Affairs·Mar 12, 14:56 UTC · Mar 12, 2024Vulnerability in the wildCVE-2024-2176260
CISA adds Fortinet FortiOS bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 10, 20:18 UTC · Feb 10, 2024Exploit / PoC in the wildCVE-2024-2176260
U.S. CISA adds Fortinet FortiOS flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 17, 14:29 UTC · Jan 17, 2025Exploit / PoC in the wildCVE-2024-55591CVE-2025-21333CVE-2025-21334+1 CVEs60
Fortinet FortiOS Flaw Exploited in Targeted Cyberattacks on Government EntitiesThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2023Exploit / PoCCVE-2022-41328CVE-2023-25610CVE-2022-4247560
A critical flaw affects Fortinet FortiOS and FortiProxy, patch it now!Security Affairs·Mar 8, 22:39 UTC · Mar 8, 2023VulnerabilityCVE-2023-2561060
Critical Fortinet FortiOS flaw exploited in the wild (CVE-2024-21762)Help Net Security·Feb 12, 00:00 UTC · Feb 12, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2022-42475+2 CVEs60
Fortinet fixes critical bugs in FortiOS, FortiProxy, and FortiClientEMSSecurity Affairs·Mar 13, 18:47 UTC · Mar 13, 2024VulnerabilityCVE-2023-42789CVE-2023-42790CVE-2023-4878860
U.S. Charges 3 Iranian Hackers and Sanctions Several Others Over Ransomware AttacksThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2022RansomwareCVE-2018-13379CVE-2019-5591CVE-2020-12812+6 CVEs60
CISA adds Log4Shell flaw to the Known Exploited Vulnerabilities CatalogSecurity Affairs·Dec 13, 13:44 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-44515CVE-2021-44168+10 CVEs60
Fortinet fixes FortiOS zero-day exploited by attackers for months (CVE-2024-55591)Help Net Security·Jan 17, 09:05 UTC · Jan 17, 2025Exploit / PoC in the wildCVE-2024-5559160
FortiOS 7.2 enables organizations to protect their hybrid networksHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2022Ransomware60
Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026Security Affairs·Jan 28, 15:58 UTC · Jan 28, 2026Vulnerability in the wildCVE-2026-24858CVE-2025-59718CVE-2025-5971960
June 2026 CVE LandscapeRecorded Future·Jul 17, 00:00 UTC · Jul 17, 2026Ransomware in the wildCVE-2026-35616CVE-2026-25939CVE-2020-17103+53 CVEs60
Chinese Hackers Exploit Fortinet ZeroThe Hacker News·Mar 21, 05:20 UTC · Mar 21, 2023Exploit / PoCCVE-2022-4132860
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News·Jun 27, 12:06 UTC · Jun 27, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs60
Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware DeliveryThe Hacker News·Feb 12, 06:21 UTC · Feb 12, 2026Malware in the wildCVE-2025-0108CVE-2024-41713CVE-2024-10914+2 CVEs60
U.S., U.K. and Australia Warn of Iranian Hackers Exploiting Microsoft, Fortinet FlawsThe Hacker News·Nov 22, 07:14 UTC · Nov 22, 2021Ransomware in the wildCVE-2021-34473CVE-2020-12812CVE-2019-5591+1 CVEs60
CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho VulnerabilitiesThe Hacker News·Sep 11, 05:58 UTC · Sep 11, 2023VulnerabilityCVE-2022-47966CVE-2022-42475CVE-2021-4422860
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Fortinet plugs critical RCE hole in FortiOS, FortiProxy (CVE-2023-25610)Help Net Security·Mar 9, 00:00 UTC · Mar 9, 2023Vulnerability in the wildCVE-2023-2561060
Fortinet fixed a critical flaw in FortiOS and FortiProxySecurity Affairs·Jul 12, 16:33 UTC · Jul 12, 2023VulnerabilityCVE-2023-3330860
Fortinet urges customers to fix actively exploited FortiOS SSLSecurity Affairs·Dec 12, 19:28 UTC · Dec 12, 2022Exploit / PoC in the wildCVE-2022-4247560
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPsCisco Talos·Jul 10, 10:00 UTC · Jul 10, 2024Ransomware60
Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active ExploitationThe Hacker News·Feb 10, 06:49 UTC · Feb 10, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23108CVE-2024-23109+2 CVEs60
Attackers target govt networks exploiting Fortinet SSL-VPN CVE-2022Security Affairs·Sep 8, 10:53 UTC · Sep 8, 2023Exploit / PoC in the wildCVE-2022-4247560
China-linked APT likely linked to Fortinet zeroSecurity Affairs·Mar 17, 19:35 UTC · Mar 17, 2023Exploit / PoCCVE-2022-4132860
CISA adds Fortinet bug to exploited vulnerabilities listThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Vulnerability in the wildCVE-2022-40684CVE-2018-1337960
Alert: 330,000 FortiGate Firewalls Still Unpatched to CVE-2023The Hacker News·Jul 4, 17:48 UTC · Jul 4, 2023Vulnerability in the wildCVE-2023-2799760
Week in review: AnyDesk phishing campaign targets employees, Microsoft fixes exploited zero-daysHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2023-43770+5 CVEs160
RansomHub Ransomware Group Targets 210 Victims Across Critical SectorsThe Hacker News·Sep 3, 12:52 UTC · Sep 3, 2024RansomwareCVE-2023-46604CVE-2023-22515CVE-2023-3519+3 CVEs60
Critical FortiOS pre-auth RCE vulnerability exploited by attackers (CVE-2022-42475)Help Net Security·Dec 13, 00:00 UTC · Dec 13, 2022Vulnerability in the wildCVE-2022-4247560
Attackers Exploit Arista VeloCloud Orchestrator Command Injection FlawThe Hacker News·Jul 28, 04:43 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16812CVE-2025-68686CVE-2026-1672360
Chinese Hackers Exploited Recent Fortinet Flaw as 0The Hacker News·Jan 20, 15:58 UTC · Jan 20, 2023Exploit / PoCCVE-2022-4247560
New Hacking Group Leaks Configuration of 15,000 Fortinet FirewallsInfosecurity Magazine·Jan 16, 12:50 UTC · Jan 16, 2025Data breachCVE-2022-40684CVE-2024-5559160