Patched FortiGates Still Leak Access Through Old Credentials

The break is not just Fortinet code flaws. Internet-facing FortiGate management and SSL-VPN portals can stay open after patching if old passwords, reused hashes, or still-valid sessions already bought an attacker access. Qualys says FortiBleed is a June 2026 cluster of credential exposure and abuse, tied to reused credentials, legacy hashes, brute-force, and prior Fortinet CVE exposure rather than one new zero-day. It maps eight Fortinet CVEs, including CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, across FortiGate, FortiOS, FortiProxy, FortiAnalyzer, and FortiWeb. The risk persists on the management plane and SSL-VPN plane after code is fixed. If the secrets or sessions were taken earlier, the appliance remains a live foothold until those access paths are revoked and replaced.

Part of the PlainSec briefing for 2026-07-09

Sources