# FortiBleed Flaw Exposed Victim's VPN Creds

Published: 2026-08-12 · Severity: elevated
Canonical: https://vorant.io/reports/1d385d00-2c06-5a32-9201-e15725c74ca7/fortibleed-flaw-exposed-victim-s-vpn-creds

> A ransomware group's leak site post shows a victim's FortiOS SSL-VPN credentials were exposed through the 2022 FortiBleed vulnerability.

This entry from ransomware.live documents a victim listing on a ransomware group's leak site, where the group claims the initial compromise involved FortiOS SSL-VPN credentials exposed via CVE-2022-40684, commonly known as FortiBleed. This vulnerability, an out-of-bounds read in FortiOS/FortiProxy SSL-VPN, allows unauthenticated attackers to retrieve sensitive memory content including credentials, and has been widely exploited since its 2022 disclosure.

The posting itself provides minimal technical detail beyond the credential-exposure claim and DNS record enumeration for the victim's domain, consistent with a standard ransomware extortion leak-site entry rather than a detailed technical writeup. No specific ransomware group, malware family, or victim sector is identified in the available text.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)

Source reporting: https://www.ransomware.live/id/QU9MLkNPTUBjbG9w

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1d385d00-2c06-5a32-9201-e15725c74ca7/fortibleed-flaw-exposed-victim-s-vpn-creds.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
