Утечка FortiBleed затронула 86 000 устройств Fortinet
Reported exploitedFortiGateFortinet VPNOur summary
CISA reports that the FortiBleed campaign impacted 86,644 Fortinet firewall and VPN gateway devices across 194 countries, with roughly half of all internet-exposed Fortinet infrastructure potentially affected. Researchers found an exposed database containing thousands of FortiGate/Fortinet VPN URLs along with logins, email addresses, and passwords in plain form, enabling attackers to intercept traffic and reuse credentials for further compromise. Fortinet says the data likely combines prior incident information and brute-force results, and references potential involvement of CVE-2026-24858 and CVE-2025-59718 and CVE-2025-59719—making credential rotation and device hardening urgent for owners.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.