Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cve, zero-day, incident, kev] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, healthcare, energy] ยท au_impact: true

FortiBleed

FortiBleed refers to the exposure of leaked credentials associated with approximately 74,000 internet-exposed Fortinet devices (firewalls and SSL VPN gateways) across government and private sectors globally. The incident prompted urgent action from Cisa and continues to reverberate across sectors.

Timeline

Date Event
June 18, 2026 CISA initial alert on Fortinet credential exposure
June 22, 2026 CISA updates alert with expanded guidance
July 2026 FortiBleed continues to dominate sector coverage across all July digests

Scope

  • ~74,000 exposed devices globally
  • Affects Fortinet firewalls and SSL VPN gateways
  • Government and private sector organisations impacted
  • Credentials leaked allowing potential unauthorised access

CISA Guidance

CISA urged organisations to immediately: (raw/digests/Cyber-Digest-2026-07-09)

  1. Terminate all active sessions on affected devices
  2. Reset all credentials (passwords, API keys, certificates)
  3. Enforce PBKDF2 hashing for stored credentials
  4. Deploy phishing-resistant MFA on all management interfaces
  5. Restrict management interfaces from the public internet
  6. Harden device configs per vendor best practices

Australian Significance

Fortinet devices are widely deployed across Australian government and critical infrastructure. Organisations under the Soci Act should prioritise remediation per Acsc guidance. (raw/digests/Cyber-Digest-2026-07-07)

Related Pages