Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CISA warns Fortinet users to secure devices after FortiBleed leak

0
Medium
Vulnerability
Published: 06/19/2026 (06/19/2026, 06:47:55 UTC)
Source: Bleeping Computer

Description

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed." [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/19/2026, 06:50:23 UTC

Technical Analysis

The FortiBleed incident involves the exposure of approximately 74,000 Fortinet firewall and VPN credentials, including plaintext passwords, discovered on an exposed server. The leaked data spans over 21,000 unique domains and 194 countries, affecting major corporations and government entities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued warnings urging affected users to secure their devices by terminating active sessions, resetting credentials, enabling phishing-resistant multifactor authentication, and restricting firewall management interfaces from public internet access. The origin of the leak remains unknown, with no confirmed link to specific vulnerabilities or exploits. The leak appears to have been leveraged by a Russian-speaking threat group conducting extensive credential attacks against Fortinet devices. No vendor patch or official remediation has been publicly confirmed.

Potential Impact

Exposure of nearly 74,000 Fortinet firewall and VPN credentials, including plaintext passwords, enables threat actors to access and potentially compromise affected devices. This impacts a broad range of organizations worldwide, including major corporations and government agencies, increasing the risk of unauthorized access, data breaches, and lateral movement within networks. The leak undermines the confidentiality and integrity of affected Fortinet devices and associated networks. The source of the leak is unknown, so further vulnerabilities or attack vectors may exist. The widespread nature of the leak and the presence of active devices online heighten the risk of exploitation.

Mitigation Recommendations

No official patch or fix has been confirmed by Fortinet or CISA at this time. CISA recommends that affected Fortinet device owners immediately terminate all SSL VPN and administrative sessions, reset all VPN and administrative passwords, and enable phishing-resistant multifactor authentication. Additionally, organizations should review logs for unauthorized access or lateral movement, restrict firewall management interfaces from public internet access, remove unauthorized accounts, and store admin credentials using the PBKDF2 hashing algorithm. These steps reduce the attack surface and help mitigate risks associated with the leaked credentials.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/","fetched":true,"fetchedAt":"2026-06-19T06:50:15.593Z","wordCount":833}

Threat ID: 6a34e6a7f198dc38c1a927f9

Added to database: 06/19/2026, 06:50:15 UTC

Last enriched: 06/19/2026, 06:50:23 UTC

Last updated: 06/20/2026, 23:06:01 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses