FortiBleed – Widespread Credential Exposure Targeting Fortinet Firewalls and SSL VPN Gateways

Release Date: 22nd June 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CERT Vanuatu advises on FortiBleed, a large-scale credential exposure campaign targeting Fortinet FortiGate Firewalls and SSL VPN gateways. Unlike a traditional software vulnerability, FortiBleed is a credential compromise campaign where attackers leverage leaked, stolen, or exposed administrator and VPN credentials to gain unauthorized access to Fortinet devices.

 

References

  1. https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
  2. https://www.cyber.gov.au/about-us/view-all-content/Reported-widespread-credential-exposure-affecting-Fortinet-Firewalls-and-VPN-Gateways
  3. https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices