
Here's a list of some notable exploited Fortinet auth bypass CVEs from 2021-2026, based on security reports (e.g., CISA KEV, FortiGuard): - CVE-2022-40684 (2022): Auth bypass in FortiOS via crafted headers; exploited for unauthorized access in govt/org networks. - CVE-2023-36634 (2023): FortiSandbox auth bypass; used in targeted attacks. - CVE-2024-47575 (2024): FortiManager missing auth; actively exploited, leading to data exfil in thousands of devices. - CVE-2025-59718 (2025): FortiCloud SSO bypass; exploited for cross-tenant access. - CVE-2026-24858 (2026): FortiOS SSO bypass; ongoing exploitation per CISA. Impacts affected orgs globally, but "hundreds of millions" of individuals is hard to verify—estimates vary by breach scope. Patch promptly.
Post summary
The post lists several Fortinet authentication bypass CVEs that have been actively exploited, stresses the need for prompt patching, and gives brief technical details.
