The verdict
Fortinet is the more vulnerable platform. It is also the more attacked one.
The gap is not close, and it does not rest on one bad year. Fortinet published 340 CVE-bearing advisories across 2023–2025. Cisco Meraki published 12. That is a factor of 28.3×.
Severity widens it further. Fortinet lost 34 advisories to the critical class; Meraki lost 0. The measure that matters most — confirmed exploitation — reads 14 against 0.
Cisco Meraki · 2023–2025
12
CVE-bearing advisories
Severity mix — 0 critical · 6 high · 6 medium · 0 low
Fortinet · 2023–2025
340
CVE-bearing advisories
Severity mix — 34 critical · 124 high · 154 medium · 28 low
The chain
How a FortiGate falls
A count does not explain why one platform draws fire. This is the chain attackers ran against internet-facing FortiGate appliances, rebuilt from published reporting of the credential campaign. Every stage is documented.
Figure 1 · attack chain · six stages, one clock
Pause, replay and speed are live controls. That a firewall compromise yields a network tap — not just a dropped session — is why attackers write tooling for it.
The volume
Two measures, one direction
The upper panel is how much a platform published. The lower panel is how much of it attackers actually used. Meraki's bars there are not small — they are zero, in all three years.
Figure 2 · disclosed vs exploited · upper: CVEs published · lower: CISA KEV additions (exploited in the wild)
Panel A counts advisories. Panel B counts additions to the exploited-in-the-wild catalog. Eight Fortinet vulnerabilities entered that catalog in 2025 alone.
Severity over the window
Severity is the highest CVSS base rating on each advisory. Year 2026 is shown for context and excluded from the verdict.
| Year | Platform | CVEs | Critical | High | Medium | Low |
|---|---|---|---|---|---|---|
| 2023 | Fortinet | 111 | 11 | 50 | 41 | 9 |
| 2023 | Meraki | 1 | 0 | 0 | 1 | 0 |
| 2024 | Fortinet | 76 | 10 | 29 | 36 | 1 |
| 2024 | Meraki | 8 | 0 | 4 | 4 | 0 |
| 2025 | Fortinet | 153 | 13 | 45 | 77 | 18 |
| 2025 | Meraki | 3 | 0 | 2 | 1 | 0 |
| 2026 YTD | Fortinet | 112 | 15 | 29 | 56 | 12 |
| 2026 YTD | Meraki | 1 | 0 | 0 | 1 | 0 |
Exploited in the wild
The catalog does not lie
Every row below is a confirmed exploitation, not a suspicion. CISA also flags the entries ransomware operators used. Meraki is absent from every year.
| Year | Platform | New KEV | Ransomware-flagged | CVEs |
|---|---|---|---|---|
| 2023 | Fortinet | 2 | 1 | CVE-2023-27997, CVE-2022-41328 |
| 2023 | Meraki | 0 | 0 | — |
| 2024 | Fortinet | 4 | 2 | CVE-2024-47575, CVE-2024-23113, CVE-2023-48788, CVE-2024-21762 |
| 2024 | Meraki | 0 | 0 | — |
| 2025 | Fortinet | 8 | 3 | CVE-2025-59718, CVE-2025-58034, CVE-2025-64446, CVE-2025-25257, CVE-2019-6693, CVE-2025-32756, CVE-2025-24472, CVE-2024-55591 |
| 2025 | Meraki | 0 | 0 | — |
| 2026 YTD | Fortinet | 8 | 0 | CVE-2026-104286, CVE-2025-25249, CVE-2025-68686, CVE-2026-25089, CVE-2026-39808, CVE-2026-21643, CVE-2026-35616, CVE-2026-24858 |
| 2026 YTD | Meraki | 0 | 0 | — |
Verified two ways: the NVD series above, and a text scan of all 1,734 catalog entries for the string “Meraki”.
The record, year by year
Three years of asymmetric pressure
Here the order carries the information, so it gets a rail. Marker size tracks the number of vulnerabilities exploited that year.
Figure 3 · timeline · the large numeral is that year's exploited-in-the-wild count
Marker area is proportional to the exploited-in-the-wild count. The 2026 marker sits outside the three-year window and is shown because it changes the buying decision.
2023
Cisco Meraki
- One product advisory, medium severity (CVE-2023-20029, Meraki onboarding).
- No exploited vulnerability. No platform breach.
Fortinet
- CVE-2023-27997, “XORtigate”: critical (CVSS 9.2) pre-authentication heap overflow in the FortiOS and FortiProxy SSL-VPN. Added to the exploited-in-the-wild catalog and flagged for ransomware.
- CVE-2022-41328, a FortiOS path traversal, also added to that catalog.
2024
Cisco Meraki
- Eight advisories. The largest group is a six-CVE denial-of-service cluster in the AnyConnect VPN server on MX and Z series gateways (CVE-2024-20498 through CVE-2024-20513).
- A Windows privilege escalation in the Systems Manager Agent, CVSS 7.3 (CVE-2024-20430).
- No exploitation reported. No platform breach.
Fortinet
- CVE-2024-21762, a FortiOS out-of-bounds write. Exploited. Flagged for ransomware.
- CVE-2024-23113, a format string flaw across multiple products. Exploited.
- CVE-2024-47575, “FortiJump”: missing authentication in FortiManager, rated 9.8. A zero-day used for espionage through managed service providers, scripted to steal managed-device IPs, credentials and configurations.
- September 2024: Fortinet disclosed its own breach. Files were taken from a third-party cloud file share. The attacker claimed 440 GB; Fortinet said the data covered under 0.3% of customers, out of a base above 500,000, with no ransomware and no encryption.
2025
Cisco Meraki
- Three advisories, including a denial of service in the AnyConnect VPN server on MX and Z series (CVE-2025-20212) and one in the ECE cloud chat feature.
- No exploitation reported. No platform breach.
- One availability incident: a cloud connectivity outage on 15 December 2025 lasting 3 hours 5 minutes, affecting cloud authentication and device-to-cloud connectivity. Not a security breach.
Fortinet
- Eight new entries in the exploited-in-the-wild catalog — the highest year in the window.
- CVE-2024-55591, an authentication bypass in FortiOS and FortiProxy. Roughly 50,000 internet-facing devices exposed. The actor tracked as Mora_001 used it to deploy the SuperBlack toolset. Ransomware-flagged.
- CVE-2025-24472, a second authentication bypass in the same products.
- CVE-2025-32756, a stack buffer overflow across multiple products.
- Three FortiWeb flaws — CVE-2025-25257, CVE-2025-64446, CVE-2025-58034 — covering SQL injection, path traversal and command injection.
- December 2025: CVE-2025-59718 and CVE-2025-59719, a cryptographic signature verification flaw enabling an authentication bypass through FortiCloud single sign-on on FortiOS, FortiWeb, FortiProxy and FortiSwitchManager. Exploited. The vendor workaround was to switch the sign-on off.
The escalation
FortiBleed
In June 2026 researchers published working administrator and SSL VPN credentials for approximately 74,000 internet-facing FortiGate appliances, drawn from more than 21,000 IP addresses across 194 countries — roughly half of all internet-facing FortiGates in existence. CISA issued an alert on 18 June 2026. The FBI and the Secret Service followed with a joint advisory.
There is no CVE and no patch, because the cause is exposure plus credential weakness: management interfaces reachable from the internet, and legacy SHA-256 password hashing that persisted after upgrades until each administrator signed in again. Captured hashes were cracked on a 45-GPU cluster, then used to enter Active Directory and Radius.
Appliances exposed
74,000
About half of all internet-facing FortiGates
Distinct IP addresses
21,000+
Credential sets verified working
Countries
194
Sectors spared: none
Cracking rig
45GPU
Hashtopolis, 12-level recursion
Who was named
The leaked attacker database carried each victim's industry, revenue and employee count. Organizations identified in it include:
| Named in the leaked dataset |
|---|
| Oracle, Chevron, Lenovo, FedEx, Fortinet, Foxconn, Samsung, Comcast, Siemens, PwC, Accenture, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and a NATO defence contractor in Turkey. |
Most affected countries
- India, United States, Taiwan, Mexico, Turkey, Thailand.
- 194 countries in total.
Most affected industries
- IT services and telecommunications, the hardest hit.
- Construction materials, construction and engineering, industrial equipment, financial services.
- Government agencies and critical infrastructure operators also appear.
The confirmed damage. A Turkish NATO defence contractor lost classified defence documents. Researchers confirmed full network compromises at organizations in Japan, Taiwan, Vietnam, Iraq and Turkey.
Meraki has no comparable entry. No dataset of Meraki customer credentials exists in public. The one Cisco incident of 2025 was corporate and adjacent: a voice-phishing attack on a Cisco representative in July 2025 opened one third-party cloud CRM instance, exporting basic profile data from Cisco.com accounts. Cisco stated that no customer confidential information and no passwords were obtained, and the Meraki platform was not involved.
The mechanism
Why the asymmetry is structural
Not luck, and not one bad CVE. Six design facts decide this comparison.
- Where the management plane lives. A Meraki device is managed from the cloud dashboard, so the customer edge publishes no administrative interface. A FortiGate is self-managed, and its management interface and SSL-VPN portal are frequently reachable from the internet. That reachability is the initial-access surface.
- Who applies the patch. Meraki firmware moves through the dashboard, so the vendor controls the upgrade path. FortiOS upgrades are customer-driven, so unpatched devices accumulate — and that long tail is what scanners find.
- Attacker payoff. A compromised firewall is a network tap. It sees authentication traffic, and its credentials open Active Directory and Radius. A denied VPN session is an inconvenience by comparison. The Meraki advisories in this window are almost entirely denial-of-service and privilege-escalation class; the Fortinet set includes pre-authentication remote code execution and authentication bypass.
- Target density. Fortinet holds roughly 15% of the global firewall market, heavily on internet-facing perimeters. One working exploit has a very large addressable set, so tooling gets written for it.
- Credential storage. FortiOS kept SHA-256 with salt for administrator credentials after the move to PBKDF2, until each administrator re-authenticated. Offline cracking was therefore practical, and that turned a configuration leak into 74,000 working logins.
- Product count. Fortinet exposes many separately reachable products — FortiOS, FortiProxy, FortiWeb, FortiManager, FortiClient EMS, FortiSandbox, FortiMail. Each is its own target with its own advisory stream. Meraki exposes one managed platform behind a dashboard.
Method and limits
How to check this, and where it is weak
- Vulnerability counts. NVD API 2.0,
keywordSearchon the vendor name, grouped by first-published date. NVD rejects date ranges longer than 120 days, so each year was sliced into windows of 110 days or fewer and the windows were summed. - Exploitation counts. CISA KEV catalog, snapshot 2026.10.04, 1,734 entries, counted by vendor project and date added.
- The zero check. All 1,734 entries were scanned for the string “Meraki” across product, name and description. The result was zero. Measured, not assumed.
- Numbers are generated. The build script refuses to emit this page if a figure disagrees with the source data.
Three limits
- The Meraki count is a floor. Keyword search matches description text, so a Meraki CVE named only in its CPE data can be missed. The true figure is equal or slightly higher. The direction of the error does not change the verdict.
- The 2026 Meraki row undercounts. Cisco published a Meraki hardening advisory on 7 October 2026, one day before this document, with seven CVEs and a CVSS base of 9.6 on the buffer overflow (CVE-2026-76464). NVD had not indexed those records when the count ran. Cisco states they were found in internal testing and are not known to be exploited. It is the first critical-class Meraki advisory in the period reviewed, and it falls outside the window.
- Breaches are qualitative. Exploitation is counted exactly, from CISA. Breach events are enumerated from public reporting, and a breach never disclosed is invisible to this method.
Sources
Where every number came from
- CISA Known Exploited Vulnerabilities catalog, JSON feed, snapshot 2026.10.04.
- NVD API 2.0,
services.nvd.nist.gov/rest/json/cves/2.0. - CISA alert, 18 June 2026: “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure”.
- Ars Technica, June 2026: “Massive breach spills credentials for thousands of sensitive networks”.
- Picus Security, 30 June 2026: “FortiBleed: Inside the Campaign That Cracked 75,000 Fortinet Firewalls”.
- Fortinet PSIRT: “Analysis of Reported Credential Compromise of FortiGate Devices”.
- CISA alert, 23 October 2024: CVE-2024-47575 added to the catalog, with Rapid7 and Google Threat Intelligence analyses.
- Cybersecurity Dive, 13 September 2024: “Fortinet customer data stolen from third-party file-sharing service”.
- Cisco advisories
cisco-sa-meraki-mx-vpn-dos-QTRHzG2andcisco-sa-hardening-meraki-os-drbEX9GH. - FortiGuard PSIRT
FG-IR-23-097andFG-IR-25-647. - Cisco Event Response: “Vishing Attack Impacting Third-Party CRM System”, August 2025.
- Meraki Status page and StatusGator outage history, 15 December 2025.