logo

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices 

ID: 5de89e78-0b5b-59df-a797-6a5c5751fc80

STIX ID: report--5de89e78-0b5b-59df-a797-6a5c5751fc80

Feed Name: Qualys Blog

Threat Score
78/100

Date Published: 2026-07-08

Date Updated: 2026-07-20

Author: Arun Pratap Singh

...
...

FortiBleed is a June 2026 cluster of large-scale credential exposure and abuse against internet‑reachable FortiGate management and SSL‑VPN gateways driven by reused or previously stolen credentials plus brute‑force/password‑spray activity rather than a single new zero‑day; vendor and government sources confirmed exploitation of specific Fortinet CVEs (notably CVE-2026-24858 and CVE-2025-59718). The report maps eight relevant CVEs to Qualys QIDs, describes reported dataset scales, outlines high‑urgency risk for internet‑exposed devices without MFA or with legacy hashes, and provides detection, QQL/VMDR/CSAM queries, and remediation/hunting guidance to inventory, patch, rotate credentials, revoke sessions, enforce MFA, and validate configuration integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.