A Tribute to Bug 959065: Fortigate's Longest Serving Employee
Nineteen releases. One bug. One cultural indictment.
Nineteen releases. One bug. One cultural indictment.
From the Editor
In an industry obsessed with "Zero Trust," it's incredibly refreshing to see a cybersecurity vendor exhibit absolute, unwavering trust in something.
For Fortinet, that "something" is Bug 959065.
For the uninitiated, Bug 959065 (Traffic Shaping counter reset) is not a vulnerability. It won't leak your passwords or invite a ransomware gang into your data center. It is merely a humble, mathematically challenged counter.
And it has just celebrated its 19th consecutive release anniversary (FortiOS 7.4.2 through 7.6.7).
Nineteen releases. Let that sink in. In the lifespan of this single bug, we've seen major UI overhauls, the dawn of generative AI, and countless rebranding campaigns. But Bug 959065 remains untouched — a steadfast pillar of stability in a chaotic world.
At this point, it's no longer a "Known Issue." It has tenure. It probably has its own badge to access the Fortinet cafeteria, a dedicated parking spot in Sunnyvale, and receives stock options. I like to imagine that the specific block of code housing this bug is cordoned off with velvet ropes, revered by junior developers as a sacred heritage site that shall never be refactored.
The Fine Art of the Feature Factory
Of course, maintaining a bug for 19 release cycles isn't an accident. It requires a highly disciplined management philosophy: The Feature Factory.
Why would you assign a developer to fix a broken counter when they could be building a new AI-native, agentic, self-healing dashboard widget? You can't put "We fixed a math glitch" on a billboard. You can't use a polished, functional codebase to justify a license price hike.
So, low-impact bugs are lovingly placed in the backlog. And then they are carried over to the next sprint. And the next. Until they become vintage. Fixing 959065 now would almost feel like destroying a piece of corporate history. It would ruin the Feng Shui of the release notes.
The Broken Window (With a View)
But if we stop admiring the sheer stamina of this bug for a moment, a slightly less funny reality emerges.
In sociology, the "Broken Windows Theory" states that if you leave a few broken windows in a building unfixed, you create an environment of apathy. It signals that no one cares, leading to more chaos.
Software engineering is exactly the same. When a vendor's QA department is culturally conditioned to ignore a highly visible, well-documented bug for 19 consecutive firmware updates, it normalizes the mess. It sets a gold standard for mediocrity. It tells the engineering team: "Polish is a myth. Just hit compile and ship it."
And that is where the irony stops. Because if a security vendor is perfectly comfortable sweeping a known, harmless bug under the rug for years because "it doesn't crash the box," you have to ask yourself a terrifying question:
What else is hiding in the dark, undocumented, complex corners of the routing daemon? What other corners were cut because the release deadline for the new shiny feature was looming?
Bug 959065 didn't stay for 19 releases by accident. It stayed because the culture let it.
Which raises a more useful question than who to blame: how do you evaluate vendors before an incident forces the conversation? That's what our upcoming Vendor Pain Index and Capital Allocation Report try to help with — not accusations, but structured analysis. Where does R&D investment actually go? How is capital allocated between engineering depth and shareholder returns? What do the numbers say about a vendor's priorities before a CVE says it for them?
We don't threaten. We analyze — and try to help you ask the right questions at the right time.
References
Bug 959065 as documented in FortiOS Known Issues across all 19 affected releases:
FortiOS 7.4.x
- FortiOS 7.4.2 — Known Issues
- FortiOS 7.4.3 — Known Issues
- FortiOS 7.4.4 — Known Issues
- FortiOS 7.4.5 — Known Issues
- FortiOS 7.4.6 — Known Issues
- FortiOS 7.4.7 — Known Issues
- FortiOS 7.4.8 — Known Issues
- FortiOS 7.4.9 — Known Issues
- FortiOS 7.4.10 — Known Issues
- FortiOS 7.4.11 — Known Issues
- FortiOS 7.4.12 — Known Issues
FortiOS 7.6.x