Fortinet Responds to FortiBleed Campaign
The FortiBleed campaign is a large-scale credential-harvesting operation targeting Fortinet firewall and VPN customers. Over 86,000 confirmed working credentials were collected by threat actors using reused credentials from previous incidents and brute-force attacks against devices with weak passwords and no multi-factor authentication (MFA). The campaign does not exploit new vulnerabilities but leverages previously known authentication bypass flaws that have been patched. Fortinet has identified compromised systems, notified affected customers, and is cooperating with law enforcement. Customers are advised to rotate credentials, enable MFA, terminate active sessions, and review configurations for unauthorized changes.
AI Analysis
Technical Summary
Fortinet's FortiBleed campaign involves threat actors harvesting credentials for Fortinet devices globally by reusing credentials from earlier incidents involving authentication bypass vulnerabilities (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719) and employing brute-force techniques against devices lacking strong password hygiene and MFA. No new vulnerabilities are exploited. The campaign resulted in a database of over 86,000 valid credentials across 194 countries. Fortinet has provided remediation guidance previously and urges customers to ensure patches are applied, credentials rotated, MFA enabled, and external management restricted. The vendor is actively notifying impacted customers and working with law enforcement.
Potential Impact
The campaign has led to the compromise of over 86,000 valid credentials for Fortinet devices worldwide, potentially allowing unauthorized access to affected firewalls and VPNs. This can result in unauthorized administrative access, exposure of internal networks, and potential further compromise. However, no new vulnerabilities are exploited; the impact arises from weak password practices and lack of MFA. The threat affects a large number of devices globally.
Mitigation Recommendations
Fortinet has released patches for the underlying authentication bypass vulnerabilities (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719) and provided detailed remediation guidance. Customers should ensure all patches are applied, rotate all administrator and VPN credentials, terminate existing admin and VPN sessions, and enable multi-factor authentication on all accounts. Additionally, review firewall and VPN configurations for unauthorized changes, check logs for unexpected access, and restrict external management access to trusted hosts. Fortinet is actively notifying impacted customers and working with law enforcement. Patch status is confirmed as fixed for the referenced CVEs.
Fortinet Responds to FortiBleed Campaign
Description
The FortiBleed campaign is a large-scale credential-harvesting operation targeting Fortinet firewall and VPN customers. Over 86,000 confirmed working credentials were collected by threat actors using reused credentials from previous incidents and brute-force attacks against devices with weak passwords and no multi-factor authentication (MFA). The campaign does not exploit new vulnerabilities but leverages previously known authentication bypass flaws that have been patched. Fortinet has identified compromised systems, notified affected customers, and is cooperating with law enforcement. Customers are advised to rotate credentials, enable MFA, terminate active sessions, and review configurations for unauthorized changes.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Fortinet's FortiBleed campaign involves threat actors harvesting credentials for Fortinet devices globally by reusing credentials from earlier incidents involving authentication bypass vulnerabilities (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719) and employing brute-force techniques against devices lacking strong password hygiene and MFA. No new vulnerabilities are exploited. The campaign resulted in a database of over 86,000 valid credentials across 194 countries. Fortinet has provided remediation guidance previously and urges customers to ensure patches are applied, credentials rotated, MFA enabled, and external management restricted. The vendor is actively notifying impacted customers and working with law enforcement.
Potential Impact
The campaign has led to the compromise of over 86,000 valid credentials for Fortinet devices worldwide, potentially allowing unauthorized access to affected firewalls and VPNs. This can result in unauthorized administrative access, exposure of internal networks, and potential further compromise. However, no new vulnerabilities are exploited; the impact arises from weak password practices and lack of MFA. The threat affects a large number of devices globally.
Mitigation Recommendations
Fortinet has released patches for the underlying authentication bypass vulnerabilities (CVE-2026-24858, CVE-2025-59718, CVE-2025-59719) and provided detailed remediation guidance. Customers should ensure all patches are applied, rotate all administrator and VPN credentials, terminate existing admin and VPN sessions, and enable multi-factor authentication on all accounts. Additionally, review firewall and VPN configurations for unauthorized changes, check logs for unexpected access, and restrict external management access to trusted hosts. Fortinet is actively notifying impacted customers and working with law enforcement. Patch status is confirmed as fixed for the referenced CVEs.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/fortinet-responds-to-fortibleed-campaign/","fetched":true,"fetchedAt":"2026-06-22T09:39:44.484Z","wordCount":987}
Threat ID: 6a3902e0eed863c81e98336a
Added to database: 06/22/2026, 09:39:44 UTC
Last enriched: 06/22/2026, 09:39:53 UTC
Last updated: 06/22/2026, 12:48:51 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.