CVE Tools

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

Qualys Security BlogBy Arun Pratap Singh13 min read

Reported exploitedFortiGateSSL-VPN

Our summary

A large-scale credential exposure campaign dubbed 'FortiBleed' is exploiting reused or previously stolen credentials to attack internet-reachable FortiGate and SSL-VPN gateways. The threat involves brute-force and password-spraying techniques, not a new zero-day vulnerability. Organizations using Fortinet products with exposed interfaces, weak authentication, or legacy hashes are at highest risk. Affected CVEs include CVE-2026-24858, CVE-2025-59718, and others. Immediate steps such as enforcing multi-factor authentication (MFA), rotating credentials, and completing PBKDF2 migration are strongly recommended.

Read at Qualys Security Blog

Below is the opening; the full story is at Qualys Security Blog.

From Qualys Security Blog

Key Takeaways

  • FortiBleed refers to June 2026 public reporting of large-scale credential exposure and abuse targeting internet-reachable FortiGate management and SSL-VPN gateways driven by credential reuse and brute-force, not a single new zero-day.
  • Risk is highest for internet-exposed FortiGate devices without MFA, with reused or legacy-hashed credentials, or prior exposure to known-exploited Fortinet CVEs.
  • A patched device can remain exposed if credentials or configuration material were stolen before remediation, especially where PBKDF2 migration and legacy-hash cleanup are incomplete.
  • Qualys provides direct QID coverage for eight relevant Fortinet CVEs, plus VMDR, ETM, and CSAM QQL queries to identify and prioritize exposed assets.
  • Defenders should inventory internet-reachable services, patch where needed, revoke sessions, rotate exposed credentials, enforce MFA, and hunt for authentication anomalies and configuration changes.…
Continue at Qualys Security Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store