Exploited in the wild FortiGate ransomware Fortinet
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
CVE Tools coverage
The FortiBleed campaign, which focuses on harvesting credentials from exposed Fortinet FortiGate systems, has been linked by SOCRadar to INC and Lynx ransomware operations—suggesting stolen logins were used for follow-on intrusions. The activity involved probing roughly 11,250 FortiGate portals, gaining admin access on 409 targets, and completing the attack chain on 354, leading to at least 12 ransomware deployments and widespread endpoint encryption. Separately, eSentire reported active exploitation of Fortinet FortiClient EMS vulnerabilities tied to CVE-2026-35616 (CVSS 9.1), enabling deployment of EKZ Stealer to harvest browser credentials.