{"record":"Fortinet evidence record","url":"https://nexalign.io/vendors/fortinet","vendor":{"slug":"fortinet","name":"Fortinet","domain":"fortinet.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-24T16:17:40.632Z","coverage":{"earliest":"2021-11-03T00:00:00.000Z","latest":"2026-07-24T16:17:40.632Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":130,"kindsOfSource":5,"attributedAdvisories":110,"knownExploited":20,"registerEntriesNotAttributable":0,"practitionerThreads":7,"independentItems":8,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":62,"latest":"2026-07-15T13:43:36.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":33,"latest":"2026-07-16T09:41:41.818Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":20,"latest":"2026-07-16T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":8,"latest":"2026-07-24T16:17:40.632Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":7,"latest":"2026-06-17T20:03:22.000Z"}],"advisories":{"shown":6,"total":110,"truncated":true,"fullList":"https://nexalign.io/vendors/fortinet/advisories","items":[{"id":"CVE-2026-39808","description":"Fortinet FortiSandbox OS Command Injection Vulnerability","severity":"critical","cvss":9.1,"knownExploited":true,"date":"2026-07-16T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-39808","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22338"]},{"id":"CVE-2026-25089","description":"Fortinet FortiSandbox OS Command Injection Vulnerability","severity":"critical","cvss":9.1,"knownExploited":true,"date":"2026-07-16T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-25089","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35443"]},{"id":"CVE-2026-21643","description":"Fortinet FortiClient EMS SQL Injection Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2026-04-13T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-21643"]},{"id":"CVE-2026-35616","description":"Fortinet FortiClient EMS Improper Access Control Vulnerability","severity":"critical","cvss":9.1,"knownExploited":true,"date":"2026-04-06T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-35616","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-18963"]},{"id":"CVE-2026-24858","description":"Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability","severity":"critical","cvss":9.4,"knownExploited":true,"date":"2026-01-27T19:18:23.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-4712","https://nvd.nist.gov/vuln/detail/CVE-2026-24858"]},{"id":"CVE-2025-59718","description":"Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability","severity":"critical","cvss":9.1,"knownExploited":true,"date":"2025-12-16T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-59718","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-202198"]}]},"practitionerThreads":{"shown":5,"total":7,"truncated":true,"items":[{"title":"FortiBleed – 75k Fortinet firewalls have admin passwords cracked","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48576048","date":"2026-06-17T20:03:22.000Z"},{"title":"FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48574257","date":"2026-06-17T18:06:04.000Z"},{"title":"Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign","context":"Hacker News","url":"https://news.ycombinator.com/item?id=45557688","date":"2025-10-12T12:20:51.000Z"},{"title":"Fortinet discloses critical bug with working exploit amid surge in brute force","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44892796","date":"2025-08-13T19:34:16.000Z"},{"title":"Fortinet critical 0-day vulnerability being actively exploited","context":"Hacker News","url":"https://news.ycombinator.com/item?id=41921176","date":"2024-10-23T02:31:53.000Z"}]},"independentCoverage":{"shown":5,"total":8,"truncated":true,"items":[{"title":"Fortinet Products | Read 1494 Reviews on G2","host":"g2.com","url":"https://www.g2.com/sellers/fortinet","date":null},{"title":"Fortinet FortiClient vs Fortinet FortiEDR (2026)","host":"peerspot.com","url":"https://www.peerspot.com/products/comparisons/fortinet-forticlient_vs_fortinet-fortiedr","date":null},{"title":"Fortinet - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Fortinet","date":null},{"title":"Fortinet consolidates SD-WAN and SASE management | Network World","host":"networkworld.com","url":"https://www.networkworld.com/article/972104/fortinet-consolidates-management-sd-wan-and-sase.html","date":null},{"title":"What is your primary use case for Fortinet FortiGate?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-fortinet-fortigate","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}