CVE Tools

Fortinet Responds to FortiBleed Campaign

SecurityWeekBy Ionut Arghire

Reported exploitedFortiGateFortiVPN

Our summary

Fortinet has responded to the ongoing FortiBleed campaign, which is reportedly targeting its customers’ firewalls and VPNs with large-scale credential harvesting rather than exploiting a new product vulnerability. The activity centers on reusing previously obtained credentials and brute-force attempts against devices with weak password practices and missing multi-factor authentication, affecting Fortinet deployments across many regions. The vendor says earlier FortiCloud SSO login bypass issues—CVE-2026-24858 and CVE-2025-59718/CVE-2025-59719—are the related defects that were patched, underscoring why users must complete the recommended remediations and harden admin/VPN access.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store