# FortiBleed: 74,000+ Fortinet Firewalls Exposed to Credential-Based Takeover
## The Threat
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent hardening advisory following the discovery of FortiBleed, a large-scale credential exposure affecting an estimated 74,000+ Fortinet devices globally. The incident involves the public disclosure of administrative credentials and VPN gateway access tokens associated with Fortinet FortiGate firewalls deployed across government agencies, critical infrastructure operators, and Fortune 500 companies. Malicious actors are actively leveraging these compromised credentials to gain unauthorized access to internet-facing devices, effectively bypassing authentication controls and providing direct administrative access to some of the most sensitive network perimeters in the world.
What makes FortiBleed particularly dangerous is its simplicity and scale. Rather than exploiting a complex vulnerability requiring sophisticated exploitation techniques, threat actors are using publicly leaked credentials to log directly into administrative interfaces and VPN gateways. This approach requires minimal sophistication but yields maximum impact: once inside, attackers gain the keys to the kingdom—the ability to modify firewall rules, extract data, plant backdoors, and conduct lateral movement into protected networks. The exposure spans 194 countries and affects organizations across multiple sectors, from financial institutions to healthcare providers to government defense contractors.
The leaked credentials appear to have originated from various sources, including misconfigured backups, exposed configuration files, and breaches of third-party service providers who manage Fortinet infrastructure. Security researchers have already documented active exploitation campaigns, with threat actors using the credentials to access networks and plant persistent access mechanisms before organizations can respond.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| Incident Name | FortiBleed |
| Affected Devices | ~74,000 Fortinet FortiGate firewalls and SSL VPN gateways |
| Geographic Scope | 194 countries; government and private sector |
| Attack Vector | Credential-based authentication bypass (no CVE required) |
| Authentication Required | None (attackers use leaked valid credentials) |
| Privilege Level Gained | Administrative / root access |
| CVSS Severity | Critical (CVSS 3.1: 9.8) |
| Related CWE | CWE-522 (Insufficiently Protected Credentials), CWE-294 (Authentication Bypass) |
| Exploitability | Active, widespread exploitation confirmed |
## Affected Products
Fortinet FortiGate Firewalls:
Fortinet SSL VPN Gateways:
Secondary Risk - Managed Service Providers:
Estimated Exposure by Sector:
## Mitigations
Immediate Actions (First 24 Hours):
1. Terminate all active sessions — Kill all existing SSL VPN and administrative sessions to prevent ongoing exploitation. Verify termination through firewall logs and session management interfaces.
2. Reset all administrative credentials — Change every administrative password, service account credential, and VPN gateway password. Prioritize internet-facing systems. Enforce minimum 16-character complexity requirements with uppercase, lowercase, numbers, and special characters.
3. Verify credential storage mechanism — Confirm your Fortinet devices are using the Password-Based Key Derivation Function 2 (PBKDF2) algorithm for password hashing. Legacy weak hashing algorithms (MD5, SHA-1) leave credentials vulnerable to cracking. Apply Fortinet's Technical Tip for enforcing PBKDF2 on FortiOS v7.2.11 and later.
Short-Term Hardening (1-7 Days):
4. Implement phishing-resistant MFA — Deploy FIDO2 hardware keys or Windows Hello for Business on all administrative accounts. Standard TOTP-based MFA provides insufficient protection against credential-based attacks. Enforce MFA on all remote access interfaces and administrative panels.
5. Conduct forensic log analysis — Review firewall logs, authentication logs, VPN access logs, and domain controller logs for the past 90 days. Search for:
- Unusual administrative logins from unfamiliar IP addresses
- Configuration changes made outside normal change windows
- Lateral movement patterns (data exfiltration, port scanning, access to sensitive servers)
- Creation of new administrative or service accounts
- Disabled logging or audit trail modifications
6. Isolate management interfaces — Remove administrative access from the public internet entirely. Restrict Fortinet management interfaces to trusted internal networks or bastion hosts. Implement jump box architecture for firewall administration.
7. Audit and disable legacy accounts — Remove all unused administrative accounts, service accounts, and test accounts. Disable any accounts that do not align with current organizational structure.
Medium-Term Defensive Measures:
8. Network segmentation review — Ensure compromised firewall access cannot lead to wholesale network compromise. Verify internal network segmentation is functioning and that a compromised firewall cannot become a pivot point for lateral movement.
9. Deploy internal threat hunting — Engage security operations center (SOC) staff to hunt for indicators of compromise (IoCs) associated with FortiBleed campaigns across internal systems.
10. Assess third-party exposure — If you use managed service providers for Fortinet administration, verify their credential management practices and ensure their accounts have been reset and MFA-protected.
## References
---
## HackWire Analysis
FortiBleed represents a critical inflection point in how enterprise security is being attacked in 2026. The shift from zero-day exploitation to credential-based campaigns reflects a maturation in threat actor capabilities and economic incentives. Why spend months developing an exploit for a vulnerability when you can buy or steal 74,000 valid admin passwords on the dark web for a fraction of the development cost? This is the new calculus of industrial-scale cyber operations.
The geographic spread across 194 countries and the mix of government and private sector targets suggests multiple threat actors with different motivations are exploiting the same credential pool. State-sponsored actors are likely using access to Fortinet firewalls for espionage and network persistence. Financially motivated cybercriminals are using the same access for ransomware staging and data theft. The fact that both are operating simultaneously means defenders face asymmetric risk: a single organizational mistake—failing to reset credentials or enable MFA—could result in breach by either actor class.
The most dangerous aspect is hidden in the logistics: many organizations won't know they were exposed until months after the initial credential leak. Fortinet devices sitting on the internet with leaked credentials don't announce themselves as compromised. Attackers often maintain quiet persistence, extracting data slowly and deploying backdoors that will survive credential resets. This means many organizations that *think* they responded quickly to FortiBleed may actually be hosting dormant backdoors planted weeks before they even heard the incident name.
The MFA requirement is non-negotiable. Phishing-resistant authentication (FIDO2 hardware keys or passwordless sign-in) will stop 99.9% of credential-based attacks, but only if it's actually enforced on external gateways. Too many organizations deploy MFA for show, then whitelist entire IP ranges or leave service accounts unprotected. That won't work here.
— HackWire Editorial
---
## Related Coverage