type: cve ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [cve, zero-day, incident, kev] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, healthcare, energy] ยท au_impact: true
FortiBleed
FortiBleed refers to the exposure of leaked credentials associated with approximately 74,000 internet-exposed Fortinet devices (firewalls and SSL VPN gateways) across government and private sectors globally. The incident prompted urgent action from Cisa and continues to reverberate across sectors.
Timeline
| Date | Event |
|---|---|
| June 18, 2026 | CISA initial alert on Fortinet credential exposure |
| June 22, 2026 | CISA updates alert with expanded guidance |
| July 2026 | FortiBleed continues to dominate sector coverage across all July digests |
Scope
- ~74,000 exposed devices globally
- Affects Fortinet firewalls and SSL VPN gateways
- Government and private sector organisations impacted
- Credentials leaked allowing potential unauthorised access
CISA Guidance
CISA urged organisations to immediately: (raw/digests/Cyber-Digest-2026-07-09)
- Terminate all active sessions on affected devices
- Reset all credentials (passwords, API keys, certificates)
- Enforce PBKDF2 hashing for stored credentials
- Deploy phishing-resistant MFA on all management interfaces
- Restrict management interfaces from the public internet
- Harden device configs per vendor best practices
Australian Significance
Fortinet devices are widely deployed across Australian government and critical infrastructure. Organisations under the Soci Act should prioritise remediation per Acsc guidance. (raw/digests/Cyber-Digest-2026-07-07)
Related Pages
- Ghostlock Cve 2026 43499 โ Another critical infrastructure vulnerability
- Acsc Cms Exploitation โ Concurrent active exploitation campaign
- Cisa Kev Catalog โ CISA's KEV tracking