Vulnerabilities & Exploits · Credential Theft
FortiBleed Becomes a Credential-Resale Problem FortiBleed has moved from exposure to reuse. The real break is a confirmed set of more than 86,000 working Fortinet logins that can be reused, sold, or pointed at specific targets, so patching the original flaws does not undo access already harvested.
Fortinet says the campaign is driven by reused credentials and brute-force attacks against weak password hygiene and no MFA, not a new Fortinet bug. The credentials cover FortiGate and SSL VPN environments in 194 countries, and the leak is now being formatted like eCrime inventory instead of a one-off dump.
That changes the threat from a leak around a vendor to direct entry into any network that still trusts a reused FortiGate or VPN password. The forward risk is focused intrusion, session abuse, and admin changes through working credentials that remain valid after the original issue is closed.
11 sources · Jun 22
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).
CISA federal remediation date Jan 30 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… EPSS 68% (99th percentile).
CISA federal remediation date Dec 23 · date passed
NVD KEV
CVSS 9.8 CRITICAL: an improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through… EPSS 29% (98th percentile).
Timeline Sources Jun 22 Cybersecurity Dive
CISA urges device hardening after thousands of Fortinet credentials compromised
Security researchers warn of a months-long FortiBleed campaign targeting western organizations.
original Jun 22 The Hacker News
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
original Jun 22 Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways - Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls and VPN gateways.
original Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-06-18
Every edition of this story: FortiBleed Becomes a Credential-Resale Problem
More from today
Vulnerabilities & Exploits · Credential Theft
FortiBleed Becomes a Credential-Resale Problem FortiBleed has moved from exposure to reuse. The real break is a confirmed set of more than 86,000 working Fortinet logins that can be reused, sold, or pointed at specific targets, so patching the original flaws does not undo access already harvested.
Fortinet says the campaign is driven by reused credentials and brute-force attacks against weak password hygiene and no MFA, not a new Fortinet bug. The credentials cover FortiGate and SSL VPN environments in 194 countries, and the leak is now being formatted like eCrime inventory instead of a one-off dump.
That changes the threat from a leak around a vendor to direct entry into any network that still trusts a reused FortiGate or VPN password. The forward risk is focused intrusion, session abuse, and admin changes through working credentials that remain valid after the original issue is closed.
11 sources · Jun 22
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).
CISA federal remediation date Jan 30 · date passed
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… EPSS 68% (99th percentile).
CISA federal remediation date Dec 23 · date passed
NVD KEV
CVSS 9.8 CRITICAL: an improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through… EPSS 29% (98th percentile).
Timeline Sources Jun 22 Cybersecurity Dive
CISA urges device hardening after thousands of Fortinet credentials compromised
Security researchers warn of a months-long FortiBleed campaign targeting western organizations.
original Jun 22 The Hacker News
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
original Jun 22 Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls, VPN gateways - Industrial Cyber
Global cybersecurity agencies warn of credential exposure in FortiBleed campaign targeting Fortinet firewalls and VPN gateways.
original Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-06-18
Every edition of this story: FortiBleed Becomes a Credential-Resale Problem
More from today