FortiBleed: Default Credential Exploitation and Mass Fortinet Compromise
A new report details a massive credential compromise campaign, dubbed "FortiBleed," which has led to the exposure of verified administrator credentials for approximately 74,000 to 86,644 internet-facing Fortinet FortiGate firewalls across 194 countries. This represents roughly half of all internet-reachable FortiGate devices worldwide. The campaign, which began as early as January 2026, is characterized by its scale, automation, and the systematic exploitation of weak security practices and vulnerabilities.
Threat actors are employing a multi-pronged approach. Initially, they conduct large-scale internet scanning to identify exposed Fortinet devices. Following identification, they attempt to authenticate using vast datasets of previously leaked credentials, many of which originate from infostealer malware infections or older breaches. This credential-stuffing phase alone accounts for billions of login attempts, indicating a highly automated infrastructure designed for continuous exploitation.
Beyond credential stuffing, attackers are also exploiting a critical authentication bypass vulnerability, CVE-2026-24858, which affects FortiCloud's SSO implementation. This flaw allows for the creation of unauthorized administrator accounts on fully patched FortiOS devices. Additionally, the campaign exploits a fundamental flaw in FortiOS credential management where administrator passwords remain stored as weaker SHA-256 hashes after upgrades from older versions, until the administrator manually logs in. Attackers have leveraged significant offline cracking infrastructure, including 45-GPU setups, to systematically break these hashes at scale.
The majority of compromised accounts, approximately 63%, were either default Fortinet system accounts or generic administrator accounts that had never been renamed, making them easy targets. Once access is gained, threat actors escalate privileges, move laterally across internal segments, and establish persistent access to critical infrastructure in various sectors, including telecommunications, government, healthcare, finance, and energy. The compromised credentials enable attackers to modify firewall rules, intercept VPN traffic, create backdoor accounts, disable logging, and stage ransomware or data exfiltration.
In response to the severity of the threat, CISA issued an emergency advisory on June 18, 2026, urging immediate session termination, credential rotation, multi-factor authentication (MFA) enforcement, and the removal of FortiGate management interfaces from public internet exposure. Organizations are advised to assume compromise if their devices are part of the exposed dataset and to take immediate remediation steps.
Read original source