AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices
ID: 74b40d5c-1250-59d7-beb8-c178c1740196
STIX ID: report--74b40d5c-1250-59d7-beb8-c178c1740196
Feed Name: Canadian Centre for Cyber Security Alerts and Advisories
The Canadian Centre for Cyber Security Alert AL26-014 (June 18, 2026) warns of a widespread "FortiBleed" campaign exposing credentials on Fortinet firewalls and VPN gateways. Exploitation can allow remote access, elevated privileges, and changes to critical security settings; the alert urges organizations to inventory and remove suspicious accounts, terminate sessions, reset passwords, enforce MFA, restrict management interfaces, and apply firmware patches addressing CVE-2024-55591 and CVE-2025-59718/59719.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
