Vulnerabilities & Exploits · Credential Theft
Patched FortiGates Still Leak Access Through Old Credentials The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access.
Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858 , CVE-2025-59718 , and CVE-2025-59719 , across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb.
The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.
1 source · Jul 8
CVEs in this update
8 CVEs
Across FortiWeb, FortiNAC-F, FortiOS, and related packages.
8 critical · 0 high · 0 medium · 0 low
7 in CISA KEV · 8 with EPSS above 1%
1 with functional or packaged public exploit code
Highest severity: CVE-2022-40684 · 9.8 CRITICAL
Highest EPSS: CVE-2018-13379 · 100%
Timeline Jul 8 Reported by Qualys Jan 30 CISA federal deadline for CVE-2026-24858 passedJan 27 CVE-2026-24858 added to CISA KEVDec 23 CISA federal deadline for CVE-2025-59718 passedDec 16 CVE-2025-59718 added to CISA KEVFeb 16 CISA federal deadline for CVE-2024-21762 passedFeb 9 CVE-2024-21762 added to CISA KEVJul 4 CISA federal deadline for CVE-2023-27997 passedJun 13 CVE-2023-27997 added to CISA KEVJan 3 CISA federal deadline for CVE-2022-42475 passedDec 13 CVE-2022-42475 added to CISA KEVNov 1 CISA federal deadline for CVE-2022-40684 passedOct 11 CVE-2022-40684 added to CISA KEVMay 3 CISA federal deadline for CVE-2018-13379 passedNov 3 CVE-2018-13379 added to CISA KEVSources Jul 8 Qualys
FortiBleed: Credential Reuse and Internet-Exposed FortiGate Risk | Qualys
FortiBleed is large-scale credential exposure and abuse targeting internet-exposed FortiGate devices, publicly reported in June 2026.
original Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-07-08
Every edition of this story: Patched FortiGates Still Leak Access Through Old Credentials
More from today
Vulnerabilities & Exploits · Credential Theft
Patched FortiGates Still Leak Access Through Old Credentials The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access.
Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858 , CVE-2025-59718 , and CVE-2025-59719 , across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb.
The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.
1 source · Jul 8
CVEs in this update
8 CVEs
Across FortiWeb, FortiNAC-F, FortiOS, and related packages.
8 critical · 0 high · 0 medium · 0 low
7 in CISA KEV · 8 with EPSS above 1%
1 with functional or packaged public exploit code
Highest severity: CVE-2022-40684 · 9.8 CRITICAL
Highest EPSS: CVE-2018-13379 · 100%
Timeline Jul 8 Reported by Qualys Jan 30 CISA federal deadline for CVE-2026-24858 passedJan 27 CVE-2026-24858 added to CISA KEVDec 23 CISA federal deadline for CVE-2025-59718 passedDec 16 CVE-2025-59718 added to CISA KEVFeb 16 CISA federal deadline for CVE-2024-21762 passedFeb 9 CVE-2024-21762 added to CISA KEVJul 4 CISA federal deadline for CVE-2023-27997 passedJun 13 CVE-2023-27997 added to CISA KEVJan 3 CISA federal deadline for CVE-2022-42475 passedDec 13 CVE-2022-42475 added to CISA KEVNov 1 CISA federal deadline for CVE-2022-40684 passedOct 11 CVE-2022-40684 added to CISA KEVMay 3 CISA federal deadline for CVE-2018-13379 passedNov 3 CVE-2018-13379 added to CISA KEVSources Jul 8 Qualys
FortiBleed: Credential Reuse and Internet-Exposed FortiGate Risk | Qualys
FortiBleed is large-scale credential exposure and abuse targeting internet-exposed FortiGate devices, publicly reported in June 2026.
original Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-07-08
Every edition of this story: Patched FortiGates Still Leak Access Through Old Credentials
More from today