Vulnerabilities · 84 days ago

FortiBleed Becomes a Credential-Resale Problem

FortiBleed has moved from exposure to reuse. The real break is a confirmed set of more than 86,000 working Fortinet logins that can be reused, sold, or pointed at specific targets, so patching the original flaws does not undo access already harvested.

Fortinet says the campaign is driven by reused credentials and brute-force attacks against weak password hygiene and no MFA, not a new Fortinet bug. The credentials cover FortiGate and SSL VPN environments in 194 countries, and the leak is now being formatted like eCrime inventory instead of a one-off dump.

That changes the threat from a leak around a vendor to direct entry into any network that still trusts a reused FortiGate or VPN password. The forward risk is focused intrusion, session abuse, and admin changes through working credentials that remain valid after the original issue is closed.

CVE-2026-24858

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).

CISA federal remediation date Jan 30 · date passed

CVE-2025-59718

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS… EPSS 68% (99th percentile).

CISA federal remediation date Dec 23 · date passed

CVE-2025-59719

NVD KEV

CVSS 9.8 CRITICAL: an improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through… EPSS 29% (98th percentile).

Timeline

Sources

11 sources covering this story

Entities

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-06-23

Editions

Related stories