Another issue, this time it’s in their sandbox
Here we go again.
My take is that years of bad security from Fortinet has lead to this problem. They piled up the sticks, poured on the gas, then the customers lit the match by opening up the ports. And to top it off, Fortinet is not the source of truth or any insight on this attack, third parties are leading the way.
Fortnet Fortibleed Page
Kevin Beaumont’s write ups
https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4
CloudSEK post
This IS NOT how you write a browser extension.
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser’s proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker’s server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-84388.
Fortinet is the best comedy show on the net.