Vulnerabilities & Exploits · Credential Theft

Patched FortiGates Still Leak Access Through Old Credentials

The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access.

Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb.

The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.

1 source · Jul 8

CVEs in this update

8 CVEs

Across FortiWeb, FortiNAC-F, FortiOS, and related packages.

8 critical · 0 high · 0 medium · 0 low

7 in CISA KEV · 8 with EPSS above 1%

1 with functional or packaged public exploit code

Highest severity: CVE-2022-40684 · 9.8 CRITICAL

Highest EPSS: CVE-2018-13379 · 100%

Timeline

Sources

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-07-08

Every edition of this story: Patched FortiGates Still Leak Access Through Old Credentials

More from today