FortiBleed exposes 75,000 Fortinet device credentials
A massive credential leak dubbed FortiBleed has exposed login credentials for over 75,000 Fortinet firewalls and VPN gateways globally, putting all internet-facing Fortinet devices at risk.
In June 2026, security researchers disclosed a critical data breach affecting Fortinet infrastructure worldwide, designated FortiBleed. A publicly accessible database contains administrative credentials for more than 75,000 Fortinet firewalls and VPN gateways. The exposure affects all Fortinet devices with management interfaces or VPN access points exposed to the internet.
Multiple national cybersecurity agencies have issued urgent guidance, including CISA, UK NCSC, and France's CERT-FR. Sophos researchers noted the credential exposure is being leveraged in brute-force campaigns targeting VPN endpoints. The scale and accessibility of the leaked credential set creates an immediate window for mass exploitation by threat actors.
France's ANSSI published their weekly bulletin highlighting this incident alongside numerous critical vulnerabilities affecting enterprise infrastructure, including CVSS 10.0-rated flaws in Atlassian Jira, Oracle WebLogic, and Google Android. The bulletin notes actively exploited vulnerabilities in Cisco Catalyst SD-WAN (CVE-2026-20262), Splunk Enterprise (CVE-2026-20253), and JCE (CVE-2026-48907). Organizations running Fortinet equipment with internet-facing interfaces should immediately rotate credentials and apply hardening measures per vendor guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-027
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free