Security dossier — 08 Oct 2026 Verdict The record Method Raw figure

Comparative security dossier — 2023–2025

Meraki vs Fortinet

Three full years, two network security platforms, one question: which one is actually holding the line — and which one is being taken apart in public.

Fortinetexploited in the wild · 2023–2025
CVE-2022-41328CVE-2023-27997CVE-2024-21762CVE-2023-48788CVE-2024-23113CVE-2024-47575CVE-2024-55591CVE-2025-24472CVE-2025-32756CVE-2019-6693CVE-2025-25257CVE-2025-64446CVE-2025-58034CVE-2025-59718CVE-2022-41328CVE-2023-27997CVE-2024-21762CVE-2023-48788CVE-2024-23113CVE-2024-47575CVE-2024-55591CVE-2025-24472CVE-2025-32756CVE-2019-6693CVE-2025-25257CVE-2025-64446CVE-2025-58034CVE-2025-59718
Merakiexploited in the wild · 2023–2025
no confirmed exploit — zero entries, every year

The verdict

Fortinet is the more vulnerable platform. It is also the more attacked one.

The gap is not close, and it does not rest on one bad year. Fortinet published 340 CVE-bearing advisories across 2023–2025. Cisco Meraki published 12. That is a factor of 28.3×.

Severity widens it further. Fortinet lost 34 advisories to the critical class; Meraki lost 0. The measure that matters most — confirmed exploitation — reads 14 against 0.

Across all 1,734 entries in the CISA Known Exploited Vulnerabilities catalog, not one names a Meraki product. Fortinet appears 31 times. Read from the catalog, not inferred from a vendor page

Cisco Meraki · 2023–2025

12

CVE-bearing advisories

Severity mix — 0 critical · 6 high · 6 medium · 0 low

Fortinet · 2023–2025

340

CVE-bearing advisories

Severity mix — 34 critical · 124 high · 154 medium · 28 low

CriticalHigh MediumLow Bar length shares one axis, so the two platforms are comparable at a glance.

The chain

How a FortiGate falls

A count does not explain why one platform draws fire. This is the chain attackers ran against internet-facing FortiGate appliances, rebuilt from published reporting of the credential campaign. Every stage is documented.

Figure 1 · attack chain · six stages, one clock

Pause, replay and speed are live controls. That a firewall compromise yields a network tap — not just a dropped session — is why attackers write tooling for it.

The volume

Two measures, one direction

The upper panel is how much a platform published. The lower panel is how much of it attackers actually used. Meraki's bars there are not small — they are zero, in all three years.

Figure 2 · disclosed vs exploited · upper: CVEs published · lower: CISA KEV additions (exploited in the wild)

Panel A counts advisories. Panel B counts additions to the exploited-in-the-wild catalog. Eight Fortinet vulnerabilities entered that catalog in 2025 alone.

Severity over the window

Severity is the highest CVSS base rating on each advisory. Year 2026 is shown for context and excluded from the verdict.

YearPlatformCVEsCriticalHighMediumLow
2023Fortinet1111150419
2023Meraki10010
2024Fortinet761029361
2024Meraki80440
2025Fortinet15313457718
2025Meraki30210
2026 YTDFortinet11215295612
2026 YTDMeraki10010

Exploited in the wild

The catalog does not lie

Every row below is a confirmed exploitation, not a suspicion. CISA also flags the entries ransomware operators used. Meraki is absent from every year.

YearPlatformNew KEVRansomware-flaggedCVEs
2023Fortinet21CVE-2023-27997, CVE-2022-41328
2023Meraki00—
2024Fortinet42CVE-2024-47575, CVE-2024-23113, CVE-2023-48788, CVE-2024-21762
2024Meraki00—
2025Fortinet83CVE-2025-59718, CVE-2025-58034, CVE-2025-64446, CVE-2025-25257, CVE-2019-6693, CVE-2025-32756, CVE-2025-24472, CVE-2024-55591
2025Meraki00—
2026 YTDFortinet80CVE-2026-104286, CVE-2025-25249, CVE-2025-68686, CVE-2026-25089, CVE-2026-39808, CVE-2026-21643, CVE-2026-35616, CVE-2026-24858
2026 YTDMeraki00—

Verified two ways: the NVD series above, and a text scan of all 1,734 catalog entries for the string “Meraki”.

The record, year by year

Three years of asymmetric pressure

Here the order carries the information, so it gets a rail. Marker size tracks the number of vulnerabilities exploited that year.

Figure 3 · timeline · the large numeral is that year's exploited-in-the-wild count

Marker area is proportional to the exploited-in-the-wild count. The 2026 marker sits outside the three-year window and is shown because it changes the buying decision.

2023

Cisco Meraki

  • One product advisory, medium severity (CVE-2023-20029, Meraki onboarding).
  • No exploited vulnerability. No platform breach.

Fortinet

  • CVE-2023-27997, “XORtigate”: critical (CVSS 9.2) pre-authentication heap overflow in the FortiOS and FortiProxy SSL-VPN. Added to the exploited-in-the-wild catalog and flagged for ransomware.
  • CVE-2022-41328, a FortiOS path traversal, also added to that catalog.

2024

Cisco Meraki

  • Eight advisories. The largest group is a six-CVE denial-of-service cluster in the AnyConnect VPN server on MX and Z series gateways (CVE-2024-20498 through CVE-2024-20513).
  • A Windows privilege escalation in the Systems Manager Agent, CVSS 7.3 (CVE-2024-20430).
  • No exploitation reported. No platform breach.

Fortinet

  • CVE-2024-21762, a FortiOS out-of-bounds write. Exploited. Flagged for ransomware.
  • CVE-2024-23113, a format string flaw across multiple products. Exploited.
  • CVE-2024-47575, “FortiJump”: missing authentication in FortiManager, rated 9.8. A zero-day used for espionage through managed service providers, scripted to steal managed-device IPs, credentials and configurations.
  • September 2024: Fortinet disclosed its own breach. Files were taken from a third-party cloud file share. The attacker claimed 440 GB; Fortinet said the data covered under 0.3% of customers, out of a base above 500,000, with no ransomware and no encryption.

2025

Cisco Meraki

  • Three advisories, including a denial of service in the AnyConnect VPN server on MX and Z series (CVE-2025-20212) and one in the ECE cloud chat feature.
  • No exploitation reported. No platform breach.
  • One availability incident: a cloud connectivity outage on 15 December 2025 lasting 3 hours 5 minutes, affecting cloud authentication and device-to-cloud connectivity. Not a security breach.

Fortinet

  • Eight new entries in the exploited-in-the-wild catalog — the highest year in the window.
  • CVE-2024-55591, an authentication bypass in FortiOS and FortiProxy. Roughly 50,000 internet-facing devices exposed. The actor tracked as Mora_001 used it to deploy the SuperBlack toolset. Ransomware-flagged.
  • CVE-2025-24472, a second authentication bypass in the same products.
  • CVE-2025-32756, a stack buffer overflow across multiple products.
  • Three FortiWeb flaws — CVE-2025-25257, CVE-2025-64446, CVE-2025-58034 — covering SQL injection, path traversal and command injection.
  • December 2025: CVE-2025-59718 and CVE-2025-59719, a cryptographic signature verification flaw enabling an authentication bypass through FortiCloud single sign-on on FortiOS, FortiWeb, FortiProxy and FortiSwitchManager. Exploited. The vendor workaround was to switch the sign-on off.

The escalation

FortiBleed

In June 2026 researchers published working administrator and SSL VPN credentials for approximately 74,000 internet-facing FortiGate appliances, drawn from more than 21,000 IP addresses across 194 countries — roughly half of all internet-facing FortiGates in existence. CISA issued an alert on 18 June 2026. The FBI and the Secret Service followed with a joint advisory.

There is no CVE and no patch, because the cause is exposure plus credential weakness: management interfaces reachable from the internet, and legacy SHA-256 password hashing that persisted after upgrades until each administrator signed in again. Captured hashes were cracked on a 45-GPU cluster, then used to enter Active Directory and Radius.

Appliances exposed

74,000

About half of all internet-facing FortiGates

Distinct IP addresses

21,000+

Credential sets verified working

Countries

194

Sectors spared: none

Cracking rig

45GPU

Hashtopolis, 12-level recursion

Who was named

The leaked attacker database carried each victim's industry, revenue and employee count. Organizations identified in it include:

Named in the leaked dataset
Oracle, Chevron, Lenovo, FedEx, Fortinet, Foxconn, Samsung, Comcast, Siemens, PwC, Accenture, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and a NATO defence contractor in Turkey.

Most affected countries

  • India, United States, Taiwan, Mexico, Turkey, Thailand.
  • 194 countries in total.

Most affected industries

  • IT services and telecommunications, the hardest hit.
  • Construction materials, construction and engineering, industrial equipment, financial services.
  • Government agencies and critical infrastructure operators also appear.

The confirmed damage. A Turkish NATO defence contractor lost classified defence documents. Researchers confirmed full network compromises at organizations in Japan, Taiwan, Vietnam, Iraq and Turkey.

Meraki has no comparable entry. No dataset of Meraki customer credentials exists in public. The one Cisco incident of 2025 was corporate and adjacent: a voice-phishing attack on a Cisco representative in July 2025 opened one third-party cloud CRM instance, exporting basic profile data from Cisco.com accounts. Cisco stated that no customer confidential information and no passwords were obtained, and the Meraki platform was not involved.

The mechanism

Why the asymmetry is structural

Not luck, and not one bad CVE. Six design facts decide this comparison.

  • Where the management plane lives. A Meraki device is managed from the cloud dashboard, so the customer edge publishes no administrative interface. A FortiGate is self-managed, and its management interface and SSL-VPN portal are frequently reachable from the internet. That reachability is the initial-access surface.
  • Who applies the patch. Meraki firmware moves through the dashboard, so the vendor controls the upgrade path. FortiOS upgrades are customer-driven, so unpatched devices accumulate — and that long tail is what scanners find.
  • Attacker payoff. A compromised firewall is a network tap. It sees authentication traffic, and its credentials open Active Directory and Radius. A denied VPN session is an inconvenience by comparison. The Meraki advisories in this window are almost entirely denial-of-service and privilege-escalation class; the Fortinet set includes pre-authentication remote code execution and authentication bypass.
  • Target density. Fortinet holds roughly 15% of the global firewall market, heavily on internet-facing perimeters. One working exploit has a very large addressable set, so tooling gets written for it.
  • Credential storage. FortiOS kept SHA-256 with salt for administrator credentials after the move to PBKDF2, until each administrator re-authenticated. Offline cracking was therefore practical, and that turned a configuration leak into 74,000 working logins.
  • Product count. Fortinet exposes many separately reachable products — FortiOS, FortiProxy, FortiWeb, FortiManager, FortiClient EMS, FortiSandbox, FortiMail. Each is its own target with its own advisory stream. Meraki exposes one managed platform behind a dashboard.

Method and limits

How to check this, and where it is weak

  • Vulnerability counts. NVD API 2.0, keywordSearch on the vendor name, grouped by first-published date. NVD rejects date ranges longer than 120 days, so each year was sliced into windows of 110 days or fewer and the windows were summed.
  • Exploitation counts. CISA KEV catalog, snapshot 2026.10.04, 1,734 entries, counted by vendor project and date added.
  • The zero check. All 1,734 entries were scanned for the string “Meraki” across product, name and description. The result was zero. Measured, not assumed.
  • Numbers are generated. The build script refuses to emit this page if a figure disagrees with the source data.

Three limits

  • The Meraki count is a floor. Keyword search matches description text, so a Meraki CVE named only in its CPE data can be missed. The true figure is equal or slightly higher. The direction of the error does not change the verdict.
  • The 2026 Meraki row undercounts. Cisco published a Meraki hardening advisory on 7 October 2026, one day before this document, with seven CVEs and a CVSS base of 9.6 on the buffer overflow (CVE-2026-76464). NVD had not indexed those records when the count ran. Cisco states they were found in internal testing and are not known to be exploited. It is the first critical-class Meraki advisory in the period reviewed, and it falls outside the window.
  • Breaches are qualitative. Exploitation is counted exactly, from CISA. Breach events are enumerated from public reporting, and a breach never disclosed is invisible to this method.

Sources

Where every number came from