FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
ID: 5de89e78-0b5b-59df-a797-6a5c5751fc80
STIX ID: report--5de89e78-0b5b-59df-a797-6a5c5751fc80
Feed Name: Qualys Blog
FortiBleed is a June 2026 cluster of large-scale credential exposure and abuse against internet‑reachable FortiGate management and SSL‑VPN gateways driven by reused or previously stolen credentials plus brute‑force/password‑spray activity rather than a single new zero‑day; vendor and government sources confirmed exploitation of specific Fortinet CVEs (notably CVE-2026-24858 and CVE-2025-59718). The report maps eight relevant CVEs to Qualys QIDs, describes reported dataset scales, outlines high‑urgency risk for internet‑exposed devices without MFA or with legacy hashes, and provides detection, QQL/VMDR/CSAM queries, and remediation/hunting guidance to inventory, patch, rotate credentials, revoke sessions, enforce MFA, and validate configuration integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
