Exploitation timeline
Threadlinqs has recorded 19 Fortinet CVEs published between and . The busiest month was 2025-12 (2 new CVEs). 16 of them (84%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 19 of 19 tracked Fortinet CVEs.
- CVE-2022-40684critical 9.8KEVRansomwareEPSS 100%
- CVE-2018-13379critical 9.1KEVRansomwareEPSS 94.5%
- CVE-2024-55591critical 9.8KEVRansomwareEPSS 94.2%
- CVE-2023-48788critical 9.8KEVRansomwareEPSS 94.1%
- CVE-2022-42475critical 9.8KEVRansomwareEPSS 94%
- CVE-2024-47575critical 9.8KEVEPSS 93.8%
- CVE-2024-21762critical 9.8KEVRansomwareEPSS 92.7%
- CVE-2023-27997critical 9.8KEVRansomwareEPSS 91%
- CVE-2025-64446critical 9.4KEVEPSS 89.5%
- CVE-2026-35616critical 9.8KEVEPSS 25.3%
- CVE-2025-59718critical 9.8KEVEPSS 7.6%
- CVE-2026-24858critical 9.8KEVEPSS 2.3%
- CVE-2025-25249high 7.4KEVEPSS 1.7%
- CVE-2025-68686medium 5.3KEVEPSS 0.5%
- CVE-2022-41328medium 6.7KEVEPSS 0.2%
- CVE-2026-104286critical 9.8KEV
- CVE-2025-59719critical 9.8EPSS 0.2%
- CVE-2026-44277critical 9.1EPSS 0.1%
- CVE-2026-26083critical 9.1EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 19 CVEs; 38 distinct Fortinet products are affected. The most frequently affected (top 20):
- Fortios 10 CVEs
- Fortiproxy 7 CVEs
- Fortiweb 3 CVEs
- Fortimanager 2 CVEs
- Fortiswitchmanager 2 CVEs
- Fim-7901e 1 CVE
- Fim-7904e 1 CVE
- Fim-7910e 1 CVE
- Fim-7920e 1 CVE
- Fim-7921f 1 CVE
- Fim-7941f 1 CVE
- FortiAuthenticator 1 CVE
- FortiMail 1 CVE
- FortiOS, FortiProxy, FortiSwitchManager 1 CVE
- FortiSandbox 1 CVE
- FortiSandbox Cloud 1 CVE
- FortiSandbox PaaS 1 CVE
- Fortianalyzer 1 CVE
- Forticlient Enterprise Management Server 1 CVE
- Forticlientems 1 CVE
Threat activity
69 tracked threat campaigns reference Fortinet products or exploit Fortinet CVEs; the 25 most recent are listed.
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacksCRITICAL
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced OperatorsMEDIUM
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)CRITICAL
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate DevicesCRITICAL
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes PoultryHIGH
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate DevicesHIGH
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone ExfiltrationCRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilitiesCRITICAL
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware GroupsMEDIUM
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors ProfiledHIGH
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812)CRITICAL
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data ExfiltrationHIGH
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion DemandsMEDIUM
- CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089)CRITICAL
- CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)CRITICAL
- CISA Orders Patch of Actively Exploited Critical FortiSandbox OS Command Injection Flaws (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813)CRITICAL
- FortiSandbox VNC Server Exposure Allows Unauthenticated Access to Scanning VMs (CVE-2026-59835)HIGH
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable routers — joint UK & allied advisoryHIGH
Threat actors targeting Fortinet
Named threat actors attributed to campaigns that involve Fortinet products or CVEs, with the number of linked campaigns:
How to prioritise Fortinet patching
This order follows the data Threadlinqs holds for Fortinet, not a generic severity checklist:
- 16 of 19 Fortinet CVEs (84%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2022-40684, CVE-2018-13379, CVE-2024-55591.
- 7 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2025-59719 (0.2%), CVE-2026-44277 (0.1%), CVE-2026-26083 (0.1%).
- 16 CVEs score Critical and 1 High on CVSS v3 (maximum 9.8, average 9.1); sequence these after KEV and high-EPSS items.
- 2 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.