Free tools Windows power users keep installed
One-click scans. No signup required.
Yes. Government and vendor reporting documents active exploitation of Fortinet vulnerabilities and campaigns targeting critical infrastructure. That does not mean every Fortinet flaw is being used by an APT, or that every affected device has been compromised. The risk depends on the product, exact software version, internet exposure, and whether exploitation is confirmed for the specific vulnerability.
What is known about APT activity against critical infrastructure?
FortiGuard Labs’ “Russian Cyber Espionage Attack” alert, released May 1, 2023 and updated December 19, 2024, says it continues to observe attempts exploiting vulnerabilities highlighted in a CISA advisory about Russian military cyber actors. FortiGuard says Unit 29155 actors have targeted government services, financial services, transportation, energy, and healthcare in NATO-member and EU countries, as well as countries in Central America and Asia, since 2020. Its stated objectives include espionage, data theft, and compromising or destroying sensitive information.
This is evidence of a threat to critical infrastructure, not proof that every targeted organization was breached or that each attack used a FortiOS vulnerability. Keep the campaign claim tied to FortiGuard’s alert and its stated scope; assess a particular device or incident using the product-specific advisory, exploitation status, and local evidence.
Which Fortinet vulnerabilities have confirmed exploitation?
Two cases in particular illustrate why defenders should check both Fortinet PSIRT advisories and the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog. A KEV listing or a vendor’s exploitation notice is a prioritization signal for that CVE; it is not evidence that every Fortinet CVE is being exploited, or that a particular network has been compromised.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Next-generation firewall for small office and branch security with NGFW, IPS, and web filtering built in
- Secure SD-WAN improves cloud and SaaS performance while maintaining consistent security policy
- Deep visibility with SSL inspection and application control to identify and govern encrypted traffic
- Simple deployment and centralized management via FortiGate Cloud or FortiManager
- Seamless integration with FortiSwitch and FortiAP for a unified, secure wired and wireless network
FortiOS CVE-2022-40684
CISA describes CVE-2022-40684 as an authentication-bypass vulnerability in Fortinet products. An unauthenticated attacker could use crafted HTTP or HTTPS requests to perform administrative operations. Treat an internet-accessible, affected management interface as urgent: verify the installed product and version against Fortinet PSIRT guidance, then apply the vendor’s fixed release or workaround for that specific configuration.
FortiManager CVE-2024-47575
This is a FortiManager vulnerability, not a FortiOS vulnerability. On October 30, 2024, CISA said Fortinet had updated its guidance and indicators of compromise for CVE-2024-47575, and the issue was included in KEV based on confirmed active exploitation. Use the FortiManager-specific PSIRT advisory to determine affected versions, remediation, and relevant indicators; do not transfer FortiOS version guidance to FortiManager.
Rank #2
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Check the product before acting on a CVE
Fortinet sells multiple products with separate software and advisories. FortiGate is the firewall family associated with FortiOS; FortiManager, FortiProxy, and FortiSwitchManager are distinct products. A CVE affecting one does not automatically affect the others. Fortinet PSIRT is the vendor’s authoritative source for affected releases, severity, attack type, and upgrade paths; CISA KEV helps identify vulnerabilities with confirmed exploitation status.
How should an organization prioritize exposed Fortinet systems?
Prioritize using the combination of exposure, product/version, vulnerability and exploitation status, and operational impact—not a product name or CVE number alone. A useful triage record for each asset includes:
Rank #3
- Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.
- Internet exposure: whether the appliance or its management, VPN, or other service is reachable from outside trusted networks.
- Product and exact version: identify whether the asset runs FortiOS or another Fortinet product, and record the complete version and relevant configuration.
- Vulnerability status: compare that version with the affected and fixed versions in the matching Fortinet PSIRT advisory; check CISA KEV for confirmed exploitation status.
- Mitigation and service impact: establish the vendor-directed fixed release or workaround, any outage or change window required, and whether the service is essential to remote access or management.
- Compromise evidence and network impact: look for relevant indicators and log activity, and determine whether the device connects to sensitive business systems or operational technology (OT).
Fortinet’s 2025 Global Threat Landscape Report says its IPS sensors detected “over 97 billion exploitation attempts” in its latest analysis. This is a vendor-reported sensor detection figure, not a count of unique attackers, successful intrusions, Fortinet-device compromises, or incidents at critical-infrastructure organizations. It supports taking broad exploitation pressure seriously, but it cannot establish that a particular Fortinet vulnerability or campaign caused a breach.
The same 2025 report says more than 40,000 vulnerabilities were added to the National Vulnerability Database in 2024, a 39% increase over 2023. That broad increase makes product-specific filtering and exploitation status especially useful: teams should not treat every newly published vulnerability as equally urgent.
Rank #4
- Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.
Fortinet’s report also gives APT shares of Lazarus 21%, Kimsuky 18%, APT28 13%, Volt Typhoon 12%, and APT29 10%. These are figures reported in that publication; they do not, on their own, identify the actors behind the FortiOS or FortiManager cases above, or establish a connection between those groups and a particular affected device.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to do after finding an exposed or potentially compromised device
Use the sequence below, coordinating changes with network and OT owners where a firewall or management server supports critical operations. The correct fixed version and workaround vary by product and advisory; do not infer them from another Fortinet CVE.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
- Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
- Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
- Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
- Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
- Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.
- Inventory reachable assets. Identify internet-facing FortiGate appliances and other Fortinet management or VPN services. Record product, exact software version, exposure, business owner, and connected network zones.
- Match each asset to its advisory. Check Fortinet PSIRT for the product and version, and check CISA KEV for the CVE’s exploitation status. Confirm affected releases and upgrade paths before scheduling a change.
- Patch or apply the vendor workaround. Prioritize affected internet-facing systems with confirmed exploitation. Use the fixed release or workaround specified for that exact product and configuration, and plan any required service interruption with the system owner.
- Restrict management access. Remove unnecessary public reachability. Limit management interfaces to trusted administrative networks or other approved access paths, and review whether remote-access services need to remain exposed.
- Review logs and indicators. Use the indicators and investigation guidance in the relevant vendor and CISA advisories. Check available device, authentication, and network logs for suspicious administrative activity or other signs of exploitation. Preserve relevant logs and escalate unexplained evidence through the incident-response process.
- Rotate credentials if exposure is plausible. If a device may have been accessed or credentials may have been exposed, rotate affected administrative and service credentials from a trusted system. Revoke or replace exposed secrets and review accounts and access that could have been created or changed.
- Validate segmentation. Confirm that a compromised edge or management system cannot provide an unrestricted path into critical business systems or OT. Restrict permitted connections to what operations require and verify the boundaries with the network owners.
Applying a fix addresses the vulnerability but does not establish that a previously exposed device is clean. If logs or indicators suggest compromise, handle the system as a potential incident: preserve evidence, involve incident responders, and assess credentials and connected networks as well as the appliance itself.
What the reporting does—and does not—establish
The documented campaign reporting and confirmed-exploitation examples justify prompt review of exposed Fortinet infrastructure, especially where management or VPN services are reachable from the internet. The available claims are specific to the cited campaign alert and CVEs; they are not an exhaustive list of APT activity involving every Fortinet product or FortiOS release. For an individual environment, current affected-version details and remediation must come from the matching Fortinet PSIRT advisory, while CISA KEV provides a separate exploitation-status check.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

