logo

AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices

ID: 74b40d5c-1250-59d7-beb8-c178c1740196

STIX ID: report--74b40d5c-1250-59d7-beb8-c178c1740196

Feed Name: Canadian Centre for Cyber Security Alerts and Advisories

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Canadian Centre for Cyber Security

...
...

The Canadian Centre for Cyber Security Alert AL26-014 (June 18, 2026) warns of a widespread "FortiBleed" campaign exposing credentials on Fortinet firewalls and VPN gateways. Exploitation can allow remote access, elevated privileges, and changes to critical security settings; the alert urges organizations to inventory and remove suspicious accounts, terminate sessions, reset passwords, enforce MFA, restrict management interfaces, and apply firmware patches addressing CVE-2024-55591 and CVE-2025-59718/59719.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.