Is Fortinet That Bad?

Another issue, this time it’s in their sandbox

1 Like

Here we go again.

2 Likes

My take is that years of bad security from Fortinet has lead to this problem. They piled up the sticks, poured on the gas, then the customers lit the match by opening up the ports. And to top it off, Fortinet is not the source of truth or any insight on this attack, third parties are leading the way.

Fortnet Fortibleed Page

Kevin Beaumont’s write ups
https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8

https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4

CloudSEK post

1 Like

This IS NOT how you write a browser extension.

Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab

TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser’s proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker’s server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-84388.

1 Like

Fortinet is the best comedy show on the net.

2 Likes