FortiBleed: 73,932 Fortinet Firewalls Compromised — Credential Extraction Campaign Analysis
Global telemetry analysis of FortiBleed: mass unauthenticated credential extraction targeting 73,932 Fortinet appliances.
This post is part of the Week of June 19, 2026 Security Roundup.
Overview
The FortiBleed campaign is a large-scale, systematic operation that has extracted and cracked administrator credentials from 73,932 Fortinet FortiGate firewall instances across 194 countries. Unlike a single zero-day exploit, FortiBleed is better understood as a convergence of known, unpatched Fortinet CVEs, weak password hashing, and infostealer credential recycling — resulting in verified working admin credentials for an estimated 30,000–75,000 devices globally.
Technical Root Causes
Hudson Rock and Arctic Wolf's analysis identifies three contributing factors:
1. Known CVEs on Unpatched Devices
The primary exploitation vector is a chain of previously disclosed Fortinet vulnerabilities — most notably CVE-2026-24858 and related path traversal / authentication bypass flaws — that enable unauthenticated access to configuration data including hashed credentials on unpatched FortiOS versions. Many organizations have not applied Fortinet patches from 2025–2026, leaving these known attack surfaces open.
2. Crackable SHA-256 Password Hashing
Older FortiOS versions stored administrator passwords as unsalted or weakly salted SHA-256 hashes. Modern GPU-based hashcat campaigns can crack common and dictionary-based passwords in minutes to hours. Attackers extracted configuration backups or credential hashes via the known CVEs, then cracked them offline.
3. Credential Reuse from Infostealer Campaigns
A portion of the credentials in the FortiBleed dataset appear to have originated from infostealer malware (RedLine, Vidar, etc.) on administrator workstations, subsequently validated against FortiGate management interfaces. This "combo list" approach accelerates credential validation at scale.
Scale and Impact
- 73,932 unique FortiGate firewall URLs identified with extracted credentials
- 21,632 affected domains
- 194 countries — globally distributed
- Verified working admin credentials for an estimated 30,000–75,000 devices
- Affected organizations span critical infrastructure, healthcare, financial services, and government
CVE Chain
- CVE-2026-24858 — FortiOS path traversal enabling config file access (primary vector)
- CVE-2026-25089 — FortiSandbox unauthenticated RCE (separate but exploited in parallel by the same threat actor cluster)
- Additional older Fortinet auth bypass CVEs enabling credential hash extraction on FortiOS 7.x and earlier
Detection
Signs your FortiGate may be in the FortiBleed dataset:
- Check Hudson Rock's public indicator list (link in references) for your firewall's public IP
- Audit administrator account last-login timestamps for unexpected access
- Review FortiGate logs for config export operations you did not initiate
- Monitor for admin logins from unexpected geographic locations or IP ranges
Remediation
# 1. Immediately rotate ALL FortiGate administrator passwords
# Use strong, unique passwords (20+ chars, random)
# 2. Apply all pending Fortinet patches — prioritize:
# FortiOS 7.4.x -> 7.4.5+
# FortiOS 7.2.x -> 7.2.10+
# FortiOS 7.0.x -> 7.0.17+
# 3. Restrict management interface access
config system interface
edit
set allowaccess https ssh
set trusted-hosts
next
end
# 4. Enable multi-factor authentication for all admin accounts
# FortiGate Admin -> System -> Administrators -> Edit -> Two-factor Authentication
# 5. Verify password hashing strength (FortiOS 7.2+ uses bcrypt by default)
get system status | grep "FortiOS"
# 6. If your IP is in the FortiBleed dataset, treat management credentials as fully compromised:
# - Rotate VPN pre-shared keys
# - Rotate SSL-VPN user credentials
# - Audit firewall policy changes for unauthorized rules
# - Check for backdoor admin accounts