basicsecurity.net
Proof, not just disclosure.
Threats / Contributors / Fortinet
Vendor security team contributor

Fortinet

cited as evidence in 85 · CNA assigner on 30 of 102 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.

fortiguard.com ↗ · home of the cited advisories

102
records cited in
deterministic count
0
finder / reporter credits
CVE.org credits
30
CVE records catalogued (CNA)
assigner
72%
avg modeled exploit prob.
FIRST EPSS, 102/102
27%
ransomware-associated
28 of 102 · CISA flag
R

Roles across the work

— find / fix / exploit / catalog, computed per record from credit type, the vendor-self-CNA gate, and the linked public exploit catalog
0
Find
record(s)
30
Fix
record(s)
0
Exploit
record(s)
0
Catalog
record(s)

Each dimension is a count of the listed records where this contributor did that job. A CNA row is fix only when the affected product is the assigner’s own; registries, coordinators, platforms, intel and research houses read as catalog, never fix. Exploit counts records where this contributor is credited as author of a public exploit / detection template in a linked catalog — we link the catalog, never host a payload.

01

Known for

— recomputed from this contributor’s own records
SurfacesEdge / remote-access infra (56), Application / other (33), Server / web platform (6), Operating system / kernel (3), Hypervisor / virtualization (3)
WeaknessInjection (39), Memory safety (15), Authentication (15), Authorization / access control (13), Path traversal / file (7)
PortfolioFortinet (30), D-Link (11), Microsoft (7), Apache (5), Adobe (4), NETGEAR (2)
02

Narrative reach

— how far this contributor’s records carry an attacker, front door → lights out
1Front door
97reach this stage
→
2Keys to the kingdom
97reach this stage
→
3Lateral reach
93reach this stage
→
4Data at risk
18reach this stage
→
5Lights out
2reach this stage

Furthest any of these records carries an attacker: 5 · Lights out. 18 of 97 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)

03

Recent highlights

— this contributor’s newest known-exploited records
04

Every record they’re cited in

— all 102, each linked to its cited source

This is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.

CVE-2018-13379Fortinet100%RWKEVCVE-2023-29300Adobe100%RWKEVCVE-2022-40684Fortinet100%RWKEVCVE-2021-45046Apache100%RWKEVCVE-2017-11882Microsoft100%RWKEVCVE-2021-22986F5100%RWKEVCVE-2021-34527Microsoft100%RWKEVCVE-2017-12615Apache100%RWKEVCVE-2022-42475Fortinet99%RWKEVCVE-2023-48788Fortinet98%RWKEVCVE-2021-40444Microsoft97%RWKEVCVE-2023-38203Adobe97%RWKEVCVE-2018-1273VMware Tanzu97%RWKEVCVE-2024-55591Fortinet94%RWKEVCVE-2024-40711Veeam90%RWKEVCVE-2017-18362Kaseya87%RWKEVCVE-2023-27997Fortinet86%RWKEVCVE-2021-1675Microsoft85%RWKEVCVE-2024-21762Fortinet83%RWKEVCVE-2018-13382Fortinet82%RWKEVCVE-2020-12812Fortinet49%RWKEVCVE-2018-13374Fortinet38%RWKEVCVE-2018-13383Fortinet34%RWKEVCVE-2024-37085VMware27%RWKEVCVE-2019-5591Fortinet18%RWKEVCVE-2024-40766SonicWall18%RWKEVCVE-2025-24472Fortinet7%RWKEVCVE-2019-6693Fortinet6%RWKEVCVE-2023-1389TP-Link100%KEVCVE-2021-1498Cisco100%KEVCVE-2012-1823PHP100%KEVCVE-2020-25506D-Link100%KEVCVE-2022-30525Zyxel100%KEVCVE-2024-45519Synacor100%KEVCVE-2015-1427Elastic100%KEVCVE-2021-36260Hikvision100%KEVCVE-2022-46169Cacti100%KEVCVE-2025-25257Fortinet100%KEVCVE-2023-38205Adobe100%KEVCVE-2022-22965VMware100%KEVCVE-2024-9465Palo Alto Networks100%KEVCVE-2021-33045Dahua100%KEVCVE-2024-38856Apache99%KEVCVE-2023-28771Zyxel99%KEVCVE-2024-12987DrayTek98%KEVCVE-2023-25717Ruckus Wireless98%KEVCVE-2024-3272D-Link98%KEVCVE-2018-19410Paessler98%KEVCVE-2023-25280D-Link98%KEVCVE-2021-45382D-Link98%KEVCVE-2021-36380Sunhillo98%KEVCVE-2021-22502Micro Focus97%KEVCVE-2024-47575Fortinet95%KEVCVE-2026-21643Fortinet94%KEVCVE-2023-38950ZKTeco92%KEVCVE-2016-3427Oracle92%KEVCVE-2025-64446Fortinet92%KEVCVE-2024-5910Palo Alto Networks92%KEVCVE-2024-11680ProjectSend92%KEVCVE-2024-8190Ivanti89%KEVCVE-2012-0151Microsoft88%KEVCVE-2021-31755Tenda87%KEVCVE-2021-40655D-Link87%KEVCVE-2026-24858Fortinet86%KEVCVE-2025-64328Sangoma85%KEVCVE-2021-27561Yealink83%KEVCVE-2015-1187D-Link and TRENDnet83%KEVCVE-2017-11826Microsoft81%KEVCVE-2013-1331Microsoft80%KEVCVE-2018-15133Laravel77%KEVCVE-2026-25089Fortinet76%KEVCVE-2012-0391Apache76%KEVCVE-2017-6334NETGEAR73%KEVCVE-2025-30066tj-actions72%KEVCVE-2016-11021D-Link69%KEVCVE-2017-6077NETGEAR69%KEVCVE-2025-59718Fortinet68%KEVCVE-2021-30632Google63%KEVCVE-2024-23113Fortinet62%KEVCVE-2021-22991F561%KEVCVE-2024-9380Ivanti60%KEVCVE-2024-8956PTZOptics59%KEVCVE-2019-19006Sangoma56%KEVCVE-2025-58034Fortinet56%KEVCVE-2022-37055D-Link56%KEVCVE-2020-29557D-Link54%KEVCVE-2013-5223D-Link51%KEVCVE-2026-39808Fortinet47%KEVCVE-2014-100005D-Link43%KEVCVE-2025-32756Fortinet30%KEVCVE-2025-68686Fortinet30%KEVCVE-2019-19356Netis28%KEVCVE-2020-9377D-Link21%KEVCVE-2023-26359Adobe17%KEVCVE-2026-34197Apache15%KEVCVE-2022-41328Fortinet11%KEVCVE-2026-35616Fortinet9%KEVCVE-2021-27137DD-WRT4%KEVCVE-2025-25249Fortinet4%KEVCVE-2021-27562Arm3%KEVCVE-2025-30154reviewdog2%KEVCVE-2021-44168Fortinet1%KEV
05

Coverage & confidence

— what this profile claims, and what it does not

Established (cited)

  • Cited in 102 known-exploited records — the list below; every one links to its public source.
  • Catalogued 30 CVE record(s) as the CNA assigner (from CVE.org).
  • Coverage gaps — stated, not hidden

  • This profile is an aggregation: it asserts only what the listed records already cite — no new external claim about the contributor is made.
  • The TYPE badge and the narrative-stage mapping are editorial (our call), labeled as such, not a sourced fact.