Widespread credential Exposure Affecting Fortinet Firewalls and VPN Gateways

Release Date: 18th June 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CERT Vanuatu advises on a widespread malicious campaign targeting Fortinet Firewalls and VPN gateways. Unlike a single software vulnerability, this campaign primarily involves the compromise, theft, and abuse of administrative and VPN credentials, enabling attackers to gain unauthorized access to Fortinet devices and connected networks.

Attackers are leveraging exposed, weak, reused, or previously compromised credentials to authenticate to Fortinet infrastructure and potentially bypass security controls without exploiting a software vulnerability.

 

References

  1. https://www.cyber.gov.au/about-us/view-all-content/Reported-widespread-credential-exposure-affecting-Fortinet-Firewalls-and-VPN-Gateways
  2. https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways