FortiGate Exposure Counts Vary Widely Depending on How the Query Is Framed
Australia's Cyber Security Centre issued an alert on 18 June 2026 warning of a widespread credential-based attack campaign targeting Fortinet firewalls and VPN gateways, which could allow attackers remote access to devices and connected networks. The alert did not cite a specific CVE or disclose how many organisations were affected, and focused on operational mitigations such as rotating credentials, enforcing MFA, and reviewing access logs. When analysts attempted to quantify exposed FortiGate devices using the ZoomEye scanning platform on 23 September 2026, results ranged from roughly 40,000 to nearly one million depending on the search query used. Each query answered a different question — broad product identification versus specific port or service exposure — meaning the figures are not interchangeable. Importantly, none of these counts indicate how many devices are actually compromised or vulnerable, highlighting how query framing can significantly distort public perception of an incident's scale.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in