News Article · Jun 22, 2026 at 10:37 AM
3 min read 0
Member
Fortinet Warns FortiBleed Campaign Exploits Weak Passwords, Not New Bugs
Security #Fortinet #FortiBleed #firewall #VPN #credential harvesting #NCSC #CVE-2026-24858 #CVE-2025-59718 #CVE-2025-59719

Fortinet Warns FortiBleed Campaign Exploits Weak Passwords, Not New Bugs

Fortinet says the FortiBleed credential-harvesting campaign does not exploit new vulnerabilities. The company has identified compromised systems and is notifying customers.

Listen to this article 3 min

Fortinet has confirmed that a large-scale credential-harvesting campaign targeting its firewalls and VPNs, tracked as FortiBleed, does not exploit any new vulnerabilities. The company said threat actors reused credentials from previous incidents and used brute-force techniques against devices with weak password hygiene and no multi-factor authentication (MFA).

As part of the campaign, attackers compiled a database of over 86,000 confirmed working credentials for Fortinet devices in 194 countries, according to SecurityWeek. The U.K. National Cyber Security Centre (NCSC) has also released guidance for affected customers.

FortiBleed leverages old flaws and AI automation

Fortinet said the prior incidents that supplied the reused credentials involved the exploitation of three FortiCloud SSO login authentication bypass security defects: CVE-2026-24858, patched in January, and CVE-2025-59718 and CVE-2025-59719, addressed in December. The company provided detailed guidance at the time of those advisories and continues to urge customers to ensure remediation steps are completed.

In March, Fortinet warned that threat actors were using AI to automate target identification and password spraying in large-scale attacks against poorly protected edge devices. FortiBleed uses the same techniques, not a new Fortinet vulnerability. The company stated that this activity is not related to any recent incident or advisory.

  • Fortinet has identified the potentially compromised systems and started notifying impacted customers.
  • The company is working with law enforcement to investigate the attacks.
  • Customers with compromised FortiGate instances should terminate admin and VPN sessions, rotate credentials, and implement MFA on all administrator and VPN user accounts.
  • Fortinet recommends upgrading to software releases that support PBKDF2 hashing of administrator credentials.
  • Customers should review firewall and VPN user accounts and configurations for unauthorized changes, check logs for unexpected admin access, and restrict external management to trusted hosts.

Broader implications for edge device security

The FortiBleed campaign underscores the persistent risk posed by weak credential hygiene and the reuse of passwords from previous breaches. The NCSC's involvement highlights the scale of the threat, which affects devices in nearly every country. Fortinet's response focuses on customer notification and remediation rather than patching new flaws, because the attack vector is old: stolen credentials and brute force.

Going forward, Fortinet customers should prioritize enabling MFA, using strong unique passwords, and applying all available patches for the three SSO bypass vulnerabilities. The company continues to monitor for related activity and will update guidance as the investigation progresses. Organizations that have not yet rotated credentials or reviewed logs should do so immediately.

Fact check

  • FortiBleed campaign compiled a database of over 86,000 confirmed working credentials for Fortinet devices in 194 countries.

    reported · source

  • The campaign does not exploit new vulnerabilities; it reuses credentials from previous incidents involving CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719.

    reported · source

  • Fortinet has identified compromised systems and started notifying impacted customers.

    reported · source

  • The NCSC has released guidance for Fortinet customers impacted by FortiBleed.

    reported · source

Source reporting (2)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 923 users online: 0 registered, 916 guests and 7 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Baiduspider Facebook Googlebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 359