LIVE · cybersecurity feed
Live wire
CVE-2026-24858high

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

A widespread issue dubbed FortiBleed has been reported, involving the large-scale exposure and abuse of credentials targeting internet-facing FortiGate devices. This problem stems from credential reuse and brute-force attacks, rather than a new vulnerability. The risk is particularly high for devices lacking multi-factor authentication or those with previously compromised credentials.

zeroday.news · 24d ago

The cybersecurity landscape is grappling with the fallout from "FortiBleed," a widespread credential abuse campaign targeting internet-exposed FortiGate devices. Public reports emerged in June 2026 detailing extensive datasets containing Fortinet-related URLs, device records, usernames, and credentials. This activity is not attributed to a single new vulnerability but rather the reuse of credentials stolen or exposed in previous incidents, combined with brute-force and password-spraying attacks.

Government agencies, including CISA and the UK NCSC, issued guidance for organizations to harden their systems and investigate potential compromises. Fortinet confirmed that the observed activity involved credential reuse, brute-force attacks, and the prior exploitation of earlier FortiCloud Single Sign-On (SSO) issues. While various reports have cited different numbers for affected records, ranging from approximately 30,800 to over 86,000, these figures represent different data subsets and validation methods and should not be aggregated into a single confirmed count.

The primary risk is concentrated on internet-reachable FortiGate management interfaces and SSL-VPN gateways. Organizations with these deployments that lack multi-factor authentication (MFA), utilize reused or legacy-hashed credentials, or have previously been affected by known exploited Fortinet vulnerabilities are at the highest risk. Even after patching a device, it can remain vulnerable if credentials or configuration data were exfiltrated prior to remediation, especially if the migration away from legacy password hashing methods like PBKDF2 is incomplete.

The potential impact of a successful compromise is significant. Attackers could gain unauthorized administrative or SSL-VPN access, establish persistent local accounts that survive patching, and potentially alter device configurations. This could lead to the disclosure of sensitive information such as network rules, certificates, and connection materials. Furthermore, embedded identity credentials, including those for Active Directory/LDAP, RADIUS/TACACS+, and API tokens, could be exposed, enabling lateral movement into downstream identity systems. The loss of trust in edge devices, disruption of remote access, tampering with security controls, and increased incident response costs are all potential consequences.

Several Fortinet Common Vulnerabilities and Exposures (CVEs) are relevant to this campaign, though not all represent direct entry vectors for the recent activity. CVE-2026-24858, a critical 9.5 CVSS score vulnerability in FortiCloud SSO authentication bypass, is considered a high-priority lookback. Fortinet has confirmed this vulnerability was exploited and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog in January 2026. Fortinet cites it as a source of credentials reused in the June 2026 campaign.

Other CVEs of note include CVE-2025-59718 and CVE-2025-59719, both related to FortiCloud SSO SAML authentication bypass with high CVSS scores. While these and other historical CVEs provide context for credential and integrity theft, the recent FortiBleed activity is primarily driven by the reuse of credentials rather than a new, widespread exploit chain.

To mitigate these risks, organizations are advised to prioritize actions based on exposure and evidence, not solely on device build numbers. This includes inventorying internet-reachable management and SSL-VPN services and reducing their public exposure. Patching devices to fixed versions is necessary but insufficient on its own.

Crucially, organizations must revoke active sessions and rotate any exposed or reused credentials. This includes local administrator and VPN accounts, as well as embedded credentials for directory services, API tokens, and SNMP strings. Enforcing MFA for all administrative and SSL-VPN access is a critical defense. Completing the migration to stronger password hashing algorithms like PBKDF2, clearing legacy hashes, and validating configuration integrity are also essential steps.

Security teams should treat findings from vulnerability scans and threat hunting queries as starting points for investigation, rather than definitive proof of compromise. Any evidence of unauthorized access, configuration changes, persistence mechanisms, log tampering, or the use of compromised credentials for downstream access should trigger a full incident response.

The long tail of exposure persists because credentials or configuration data stolen in past incidents can remain potent tools for attackers even after devices are patched. This is particularly true where legacy hashing mechanisms have not been fully addressed. Organizations are urged to actively hunt for authentication anomalies and configuration changes that might indicate ongoing compromise.

fortinetfortigatecredentialsvpnmfa
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.