Vulnerabilities · 68 days ago
Patched FortiGates Still Leak Access Through Old Credentials The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access.
Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858 , CVE-2025-59718 , and CVE-2025-59719 , across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb.
The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.
CVEs in this update
8 CVEs
Across FortiWeb, FortiNAC-F, FortiOS, and related packages.
8 critical · 0 high · 0 medium · 0 low
7 in CISA KEV · 8 with EPSS above 1%
1 with functional or packaged public exploit code
Highest severity: CVE-2022-40684 · 9.8 CRITICAL
Highest EPSS: CVE-2018-13379 · 100%
Timeline Jul 8 Reported by Qualys Jan 30 CISA federal deadline for CVE-2026-24858 passedJan 27 CVE-2026-24858 added to CISA KEVDec 23 CISA federal deadline for CVE-2025-59718 passedDec 16 CVE-2025-59718 added to CISA KEVFeb 16 CISA federal deadline for CVE-2024-21762 passedFeb 9 CVE-2024-21762 added to CISA KEVJul 4 CISA federal deadline for CVE-2023-27997 passedJun 13 CVE-2023-27997 added to CISA KEVJan 3 CISA federal deadline for CVE-2022-42475 passedDec 13 CVE-2022-42475 added to CISA KEVNov 1 CISA federal deadline for CVE-2022-40684 passedOct 11 CVE-2022-40684 added to CISA KEVMay 3 CISA federal deadline for CVE-2018-13379 passedNov 3 CVE-2018-13379 added to CISA KEVSources 1 source covering this story
Entities CVE-2026-24858 CVE-2025-59718 CVE-2025-59719 CVE-2018-13379 Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-07-09
Editions Related stories
Vulnerabilities · 68 days ago
Patched FortiGates Still Leak Access Through Old Credentials The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access.
Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858 , CVE-2025-59718 , and CVE-2025-59719 , across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb.
The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.
CVEs in this update
8 CVEs
Across FortiWeb, FortiNAC-F, FortiOS, and related packages.
8 critical · 0 high · 0 medium · 0 low
7 in CISA KEV · 8 with EPSS above 1%
1 with functional or packaged public exploit code
Highest severity: CVE-2022-40684 · 9.8 CRITICAL
Highest EPSS: CVE-2018-13379 · 100%
Timeline Jul 8 Reported by Qualys Jan 30 CISA federal deadline for CVE-2026-24858 passedJan 27 CVE-2026-24858 added to CISA KEVDec 23 CISA federal deadline for CVE-2025-59718 passedDec 16 CVE-2025-59718 added to CISA KEVFeb 16 CISA federal deadline for CVE-2024-21762 passedFeb 9 CVE-2024-21762 added to CISA KEVJul 4 CISA federal deadline for CVE-2023-27997 passedJun 13 CVE-2023-27997 added to CISA KEVJan 3 CISA federal deadline for CVE-2022-42475 passedDec 13 CVE-2022-42475 added to CISA KEVNov 1 CISA federal deadline for CVE-2022-40684 passedOct 11 CVE-2022-40684 added to CISA KEVMay 3 CISA federal deadline for CVE-2018-13379 passedNov 3 CVE-2018-13379 added to CISA KEVSources 1 source covering this story
Entities CVE-2026-24858 CVE-2025-59718 CVE-2025-59719 CVE-2018-13379 Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-07-09
Editions Related stories