# FortiBleed Flaw Tied to Ransomware Leak

Published: 2026-08-26 · Severity: elevated
Canonical: https://vorant.io/reports/e9760ea0-65f9-59f0-86d9-268eeba1120d/fortibleed-flaw-tied-to-ransomware-leak

> A victim listed on a ransomware leak site reportedly had its FortiOS SSL-VPN credentials exposed via the 2022 FortiBleed authentication bypass flaw.

This is a brief victim-notification entry from Ransomware.live, a site that indexes ransomware group leak-site postings. The entry states that the compromised organization's FortiOS SSL-VPN credentials were exposed through what it terms the "FortiBleed" leak, referencing CVE-2022-40684, an authentication bypass vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager that was disclosed and patched in 2022. The posting includes DNS records for the victim's domain and a screenshot of the leak, but no victim name, actor attribution, malware family, or technical indicators are provided in the available text.

The entry offers no evidence of a specific ransomware group, no named threat actor, and no malware sample details, limiting actionable intelligence. The core takeaway for defenders is a reminder that unpatched or previously-exploited Fortinet SSL-VPN authentication bypass vulnerabilities (CVE-2022-40684) continue to be cited as initial access vectors in ransomware-related compromises, underscoring the importance of verifying patch status and rotating credentials on any FortiOS/FortiProxy devices that were ever exposed to this flaw, even if patched after the fact.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)

Source reporting: https://www.ransomware.live/id/Y2djZ2Fib24uY29tQGtyeWJpdA==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e9760ea0-65f9-59f0-86d9-268eeba1120d/fortibleed-flaw-tied-to-ransomware-leak.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
