Exploited in the wild FortiGate network-edge SSL-VPN Fortinet ddos-botnet
FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
CVE Tools coverage
A large-scale credential exposure campaign dubbed 'FortiBleed' is exploiting reused or previously stolen credentials to attack internet-reachable FortiGate and SSL-VPN gateways. The threat involves brute-force and password-spraying techniques, not a new zero-day vulnerability. Organizations using Fortinet products with exposed interfaces, weak authentication, or legacy hashes are at highest risk. Affected CVEs include CVE-2026-24858, CVE-2025-59718, and others. Immediate steps such as enforcing multi-factor authentication (MFA), rotating credentials, and completing PBKDF2 migration are strongly recommended.
Key Takeaways
- FortiBleed refers to June 2026 public reporting of large-scale credential exposure and abuse targeting internet-reachable FortiGate management and SSL-VPN gateways driven by credential reuse and brute-force, not a single new zero-day.
- Risk is highest for internet-exposed FortiGate devices without MFA, with reused or legacy-hashed credentials, or prior exposure to known-exploited Fortinet CVEs.
- A patched device can remain exposed if credentials or configuration material were stolen before remediation, especially where PBKDF2 migration and legacy-hash cleanup are incomplete.
- Qualys provides direct QID coverage for eight relevant Fortinet CVEs, plus VMDR, ETM, and CSAM QQL queries to identify and prioritize exposed assets.
- Defenders should inventory internet-reachable services, patch where needed, revoke sessions, rotate exposed credentials, enforce MFA, and hunt for authentication anomalies and configuration changes.…