Fortinet's 2026 Attack Surface Moved to the Management Plane. Patch It in That Order.
For five years the Fortinet story was the SSL-VPN. Patch the VPN, and you had patched the thing attackers were hitting. That is no longer true. We went through every Fortinet entry in CISA's Known Exploited Vulnerabilities catalog, the list of bugs CISA has confirmed are being used in real attacks, and sorted each one by what it actually lets an attacker reach. From 2022 through 2024, 5 of the 11 Fortinet additions were SSL-VPN entry bugs. In 2025 and 2026 so far, 0 of 16 are. Fourteen of the 16 hit an admin login, a management channel, or a separate management or security product that sits beside the firewall. The attack surface moved. Your patch order should move with it.
This is a patch-priority post, not a scoop. We make no claim to have seen any of this first. Every bug below was found and disclosed by someone else, and we name them.
The count
Fortinet has 31 entries in CISA's KEV catalog (version 2026.10.04). Eight were added in 2025 and eight more in 2026 so far. That pace is the first point: Fortinet is a chronic repeat offender. Across the whole KEV catalog over the past 365 days, a product's past KEV count predicts its new additions with a Spearman rank correlation of 0.55, and 54 percent of new additions land on products that were already on the list. Fortinet is the textbook case.
The 2026 list, with the dates CISA added each one:
January 27: CVE-2026-24858. A FortiCloud single sign-on flaw in FortiOS, FortiManager, FortiAnalyzer and FortiProxy. Anyone with their own FortiCloud account and a registered device could log into other customers' devices. CISA gave federal agencies three days.
April 6: CVE-2026-35616, FortiClient EMS. Improper access control, unauthenticated code execution.
April 13: CVE-2026-21643, FortiClient EMS again. Unauthenticated SQL injection leading to code execution. EMS is the server that manages every FortiClient endpoint agent in a company.
July 16: CVE-2026-25089 and CVE-2026-39808, both FortiSandbox. Two unauthenticated command-injection bugs in the box that is supposed to detonate suspicious files safely.
July 27: CVE-2025-68686, FortiOS. A bypass of the fix Fortinet shipped for the symbolic-link persistence trick attackers used on already-compromised FortiGates. Fortinet rates it 5.3, and its own advisory says it only works after the device has been compromised another way.
September 9: CVE-2025-25249, FortiOS, FortiSwitchManager and FortiSASE. A heap overflow in the cw_acd daemon, which handles CAPWAP, the control protocol FortiGates use to manage access points and switches. Fortinet's workaround is to remove "fabric" access from interfaces or block CAPWAP control ports 5246 to 5249.
October 1: CVE-2026-104286, FortiMail. Path traversal plus a null-byte trick that lets an unauthenticated attacker write arbitrary files on the mail gateway. Fortinet scores it 9.8 (advisory FG-IR-26-175). It was published to the National Vulnerability Database and added to KEV on the same day.
Only three of 2026's eight touch FortiOS at all. The other five hit EMS twice, FortiSandbox twice and FortiMail once. And the three that do touch FortiOS are a cloud-login bypass, a management-protocol bug and a post-break-in persistence bug. None of them is "send a packet to the VPN portal and get a shell," which is what CVE-2022-42475, CVE-2023-27997 and CVE-2024-21762 were.
2025 was the warning
The shift started last year. January 2025 brought CVE-2024-55591, which gave an unauthenticated attacker super-admin rights through the Node.js websocket module behind the FortiOS admin interface. March brought CVE-2025-24472, super-admin again, this time through crafted Security Fabric proxy requests. FortiWeb, Fortinet's web application firewall, took three KEV entries between July and November. December brought CVE-2025-59718, a forged SAML message that bypassed FortiCloud SSO login on FortiOS, FortiProxy, FortiWeb and FortiSwitchManager.
Then January 2026 brought the second FortiCloud SSO bug, CVE-2026-24858. Two KEV entries in six weeks on the same login feature is the clearest signal in this whole data set.
The FortiCloud SSO setting you may not know you turned on
Here is the part a small team can act on today. Fortinet's own December 2025 advisory (FG-IR-25-647) says FortiCloud SSO login is off in factory settings, but "when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch 'Allow administrative login using FortiCloud SSO' in the registration page, FortiCloud SSO login is enabled upon registration."
In plain terms: if someone registered your FortiGate through the web interface and clicked through, admin login through FortiCloud may be switched on. That is the feature both SSO bugs went through. If you do not use it, turn it off. In the GUI it is under System, then Settings, "Allow administrative login using FortiCloud SSO." On the command line it is config system global, then set admin-forticloud-sso-login disable, then end.
Fair to Fortinet
Fortinet's security team publishes fast and coordinates with CISA. The FortiMail bug went into the national database and onto the KEV list on the same day. Volexity's FortiClient report, below, shows Fortinet acknowledging a report within a week, though public guidance took five months. Disclosure is not the problem. The problem is cadence: eight confirmed-exploited bugs a year, spread across a product family most shops cannot inventory, let alone patch, in the three or four days CISA now gives federal agencies.
The softer attacks around the brand
The KEV list is not the only place Fortinet shows up in our data. Three other entries are worth knowing about, and all three came from someone else's research.
A Fortinet look-alike domain used as malware command-and-control. Elastic Security Labs documented the FINALDRAFT backdoor and its PATHLOADER loader in February 2025 (You've Got Malware: FINALDRAFT Hides in Your Drafts, by Cyril François, Jia Yu Chan, Salim Bitam and Daniel Stepanic). PATHLOADER's configuration pulls its encrypted payload from support.fortineat.com, with an extra "a" in Fortinet, alongside poster.checkponit.com, a Check Point look-alike. Elastic says the domains "purposely typosquat real known vendors, CheckPoint and Fortinet," and that fortineat.com was registered on November 8, 2023. Both fortineat.com and support.fortineat.com are in our feed at confidence 70. We ingested them yesterday, October 5, 2026, roughly 20 months after Elastic published. That date is when we added Elastic's work, not when anyone first saw the domain. The credit is Elastic's.
A squat on Fortinet's own npm name. Fortinet's public GitHub repository fortinet/autoscale-core, which holds the code for autoscaling FortiGate virtual machines in the cloud, declares a package called @fortinet/fortigate-autoscale at version 3.5.4. That package was never published on the public npm registry under Fortinet's control. On January 18, 2026, someone published a package under exactly that name with the version number 1.0.1768733010. The long number is a Unix timestamp for that same morning, 10:43 UTC. Four days later GitHub's malware advisory team and Amazon Inspector flagged it as malicious, and the open-source vulnerability database OSV recorded it as MAL-2026-453. npm replaced it with a 0.0.1-security placeholder. This is the dependency-confusion pattern: if a build system looks for a private package name on the public registry and finds one there first, it installs the stranger's code. An older, unscoped cousin, fortigate-autoscale-core, was created on npm in January 2022 and flagged as malicious in June 2022 (MAL-2022-3113). Both names are on our malicious-package deny-list and return "block" from our check-package tool. We do not know who published either one or what the code did. The advisories do not say.
A FortiClient flaw used to steal VPN passwords. Volexity reported in November 2024 that a group it calls BrazenBamboo built a plugin for its DEEPDATA malware that pulls VPN usernames, passwords, gateways and ports out of the memory of the FortiClient VPN process on Windows (BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA, by Callum Roxan, Charlie Gardner and Paul Rascagneres). Volexity reported it to Fortinet in July 2024, and Fortinet published guidance that December. Four file hashes from that report have been in our feed since September 9, 2026, credited to Volexity. Again: that is our ingest date for their work.
What we cannot see
Our edge honeypots have logged 134,357 records. Not one of them is a genuine FortiOS exploit probe. That is not because nobody is attacking FortiGates. It is because our decoys pretend to be web apps and APIs, not firewall appliances, so FortiGate exploit traffic has no reason to come to us. We are structurally blind to it, and nothing in this post should be read as us seeing Fortinet exploitation first-hand. One trap for anyone grepping their own logs: we did see four requests for "/.env.fortify". That is a spray for the environment file of Laravel Fortify, a PHP login library. It has nothing to do with Fortinet.
Our earlier coverage
We first covered the FortiClient EMS SQL injection (CVE-2026-21643) on April 4, after exploitation had already begun: Another Day, Another Management Console Owned. We wrote about the FortiGate credential dump in June (FortiBleed Is Not a Campaign. It Is an Audit Result.) and about ransomware crews using those credentials in July (The FortiGate Credentials Feeding This Ransomware Wave). We covered FortiSandbox returning to KEV on July 17 (FortiSandbox Is Back on CISA's Exploited List) and the FortiOS persistence-fix bypass on July 29 (Two Bugs Hit KEV the Same Day). We had no dedicated post on CVE-2025-25249 or on the FortiMail bug, CVE-2026-104286, until this one.
What to do this week
This is written for a small team with one firewall person, or none.
Step one: patch in this order. FortiMail first if you run it, because CVE-2026-104286 is unauthenticated, rated 9.8 and was added to KEV five days ago. Then FortiClient EMS and FortiSandbox, because they are servers that control or inspect everything else and both had two exploited bugs this year. Then FortiOS for CVE-2025-25249 and CVE-2026-24858. Then everything else on Fortinet's PSIRT page that you own.
Step two: take management interfaces off the internet. The FortiGate admin page, EMS, FortiSandbox, FortiManager and FortiAnalyzer should be reachable only from an internal management network or over a VPN. Fourteen of the 16 bugs above sit in an admin login, a management channel, or a management or security server. Keeping those off the internet will not fix the bugs, but it shrinks who can reach them from everyone to your own staff.
Step three: check the FortiCloud SSO setting described above, and turn it off if nobody uses it.
Step four: if you do not manage access points or switches from the FortiGate, follow Fortinet's workaround for CVE-2025-25249 and remove fabric access from internet-facing interfaces.
Step five: pin your npm scopes. If your build pulls any package that starts with @fortinet, or with the name of any private package you use, make sure your npm configuration points that scope at the registry you trust, and check new dependencies against a malicious-package list before installing. Our check-package tool does this for free.
Step six: if you run the FortiClient VPN on Windows, keep it current, and treat any Windows machine with an infostealer infection as one whose VPN password is gone. Rotate it.
The opinion
We think, at about 80 percent confidence, that Fortinet will add at least one more KEV entry before the end of 2026, at its current pace of about eight a year, and at about 70 percent that the next one lands in a management or companion product rather than the VPN. The rest covers a quiet quarter or a return to VPN bugs. The lesson does not depend on which one happens. The firewall is no longer one box with one door. It is a family of servers that manage, inspect, sign in and phone home, and each of them is a door. Inventory all of them, keep their admin pages off the internet, and patch the managers before the managed.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=fortinet-2026-attack-surface-moved-to-management-plane



Comments