<- all articles

FortiBleed: Credential Exposure in Fortinet Devices

A critical vulnerability exposing 74,000 Fortinet devices to cyber attacks via leaked credentials.

What Changed Operationally

The operational landscape for network security has shifted abruptly following the discovery of a widespread credential exposure affecting a significant portion of the internet-facing Fortinet device fleet. The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive urging organizations to harden their Fortinet devices after confirming global reports that malicious cyber actors have targeted these systems using compromised credentials. This activity, identified as the "FortiBleed" campaign, has demonstrated a capability to breach network perimeters by exploiting the exposure of administrator credentials. The breach impacts approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways, creating a widespread vulnerability that transcends organizational boundaries and affects both government and private sector entities.

The operational implications of this exposure are severe, as the compromise of these devices provides attackers with direct access to critical network infrastructure. The attackers are utilizing the leaked credentials to gain unauthorized entry into networks, potentially leading to lateral movement, data exfiltration, or the deployment of additional malicious payloads. The scale of the exposure, affecting tens of thousands of gateways globally, indicates a systemic failure in credential management and storage rather than a series of isolated incidents. Consequently, the immediate priority for affected organizations is to validate the integrity of their administrator accounts and enforce stricter authentication protocols to prevent further exploitation.

Credential Exposure and Hash Function Requirements

The core of the vulnerability lies in the exposure of administrator credentials associated with the compromised devices. The scope of this exposure encompasses approximately 74,000 Fortinet devices, a figure corroborated by reports indicating that roughly half of the internet-facing Fortinet firewall fleet has been impacted. This widespread leakage suggests that the credentials were not secured adequately, either through weak storage mechanisms or insufficient transmission encryption. The attackers have leveraged these exposed credentials to initiate the FortiBleed campaign, gaining footholds in networks that rely on Fortinet hardware for perimeter defense and remote access.

How The Capability Fits Together

To address the underlying security flaw, Fortinet has updated its technical guidance, specifically recommending the enforcement of the PBKDF2 (Password-Based Key Derivation Function 2) as the hash function for administrator accounts in FortiOS versions 7.2.11 and later. This recommendation is critical because PBKDF2 is designed to slow down the process of hashing passwords, making it significantly more difficult for attackers to use brute-force or rainbow table attacks to recover plain-text passwords from stored hashes. By mandating this specific hashing algorithm, Fortinet aims to increase the computational cost of credential recovery, thereby mitigating the risk posed by the leaked credentials.

Scope of the FortiBleed Campaign

The FortiBleed campaign represents a coordinated and global effort to exploit the exposed credentials of Fortinet devices. The impact of this campaign is not limited to a specific region but has been observed across 194 countries, highlighting the pervasive nature of the vulnerability. Reports from security firms such as SOCRadar and Hudson Rock indicate that the compromise involves over 80,000 Fortinet firewalls, suggesting that the total number of affected devices may be higher than the initial estimates. This global reach underscores the necessity for a unified response from security vendors and government agencies to contain the threat.

It is important to clarify the specific capabilities and limitations of the FortiBleed campaign based on the available reports. The primary objective of the attackers appears to be the unauthorized access and control of the compromised devices. While the reports confirm the use of leaked credentials to breach networks, they do not explicitly detail the full range of post-exploitation activities performed by the actors. However, the potential for these actors to deploy persistent backdoors, conduct data theft, or pivot to other systems within the compromised network remains a significant operational risk. Organizations must assume that the attackers have sufficient access to disrupt critical business functions or steal sensitive information.

Operational Impact

Administrator and Engineer Impact

The FortiBleed campaign has introduced a significant operational burden on administrators responsible for securing network perimeters. The compromise of approximately 74,000 Fortinet devices, including firewalls and VPN gateways, means that engineers must treat the exposure of credentials as a critical incident. The impact is not limited to immediate access denial; it extends to the complex process of validating the integrity of the entire fleet. Administrators must now perform a forensic review of access logs to determine the scope of the breach, a task that is resource-intensive and requires immediate attention to prevent lateral movement within the network.

For engineers, the technical implications of FortiBleed necessitate a rigorous re-evaluation of authentication mechanisms. The compromise of credentials implies that default or weak passwords may have been utilized, or that multi-factor authentication (MFA) was not enforced. The responsibility shifts toward implementing stricter identity governance. This involves auditing all administrator accounts to ensure that they adhere to the latest security standards, specifically the requirement to enforce PBKDF2 as the hash function for administrator accounts in FortiOS v7.2.11 and later. Failure to enforce these hashing standards leaves the system vulnerable to offline brute-force attacks, compounding the risk posed by the credential exposure.

Prerequisites and Access Constraints

Rollout And Governance Decisions

Implementing the necessary mitigations for FortiBleed requires specific technical prerequisites and access controls that may not be immediately available in all environments. The enforcement of PBKDF2 as the hash function is a configuration change that must be applied at the device level. This requires root or administrative access to the FortiOS operating system, which may be restricted in environments with strict separation of duties. Administrators must verify that they possess the necessary permissions to modify user authentication settings without triggering unnecessary alerts or requiring elevated privileges that could introduce new risks.

Furthermore, the scope of the remediation effort is constrained by the version of the FortiOS operating system running on the devices. The requirement to enforce PBKDF2 applies specifically to FortiOS v7.2.11 and later. This creates a tiered access and remediation strategy where engineers must first identify the firmware versions of their exposed devices. Devices running older versions may not support the PBKDF2 hashing algorithm, limiting the ability to harden them against offline credential attacks. Consequently, the remediation plan must account for the upgrade path required to bring legacy devices into compliance with the new security standards.

Governance and Evaluation Approach

A realistic evaluation of the FortiBleed impact requires a structured governance approach that prioritizes high-risk assets. Administrators should not attempt to remediate every device simultaneously, as this could lead to configuration drift or service disruption. Instead, a pilot program should be established to test the effectiveness of the PBKDF2 enforcement and credential rotation on a subset of devices. This allows the engineering team to validate that the changes do not introduce compatibility issues with existing authentication systems or third-party identity providers before a full rollout.

The decision-making process for the rollout must be data-driven, focusing on the exposure of credentials rather than the mere existence of the devices. Administrators should categorize devices based on their internet-facing status and their role in the network infrastructure. Devices that act as VPN gateways or perimeter firewalls should be prioritized for immediate hardening due to their critical role in network access. A phased approach ensures that the most vulnerable points are secured first, while the governance framework provides the oversight needed to track progress and ensure that all devices are brought into compliance with the updated security posture.

Failure Modes And Limits

Failure Modes and Operational Risks

The FortiBleed incident highlights a critical failure mode where the integrity of administrative credentials is compromised, leading to widespread unauthorized access. CISA has reported that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using these compromised credentials. This specific attack vector, identified as FortiBleed, relies on the exposure of leaked credentials associated with approximately 74,000 Fortinet devices. The operational impact of this exposure extends beyond simple account takeover; it represents a systemic vulnerability where the foundational trust in the network's perimeter is eroded. When credentials are leaked, the attackers do not merely gain a temporary foothold; they often leverage these credentials to establish persistent access, potentially bypassing traditional perimeter defenses and moving laterally within the network infrastructure.

Security And Privacy Considerations

The scale of the exposure poses a significant risk to network stability and continuity of operations. Reports indicate that the compromised credentials affect a vast array of critical infrastructure components, including firewalls and virtual private network (VPN) gateways. The compromise of VPN gateways is particularly dangerous, as it allows attackers to impersonate administrators and establish secure tunnels into the network. Furthermore, the involvement of approximately 73,932 firewalls in the leak suggests that a substantial portion of an organization's internet-facing fleet may be compromised simultaneously. This widespread exposure complicates incident response efforts, as administrators must rapidly assess the extent of the breach across multiple disparate devices to prevent further exploitation.

Security and Privacy Considerations

The security implications of the FortiBleed campaign necessitate a rigorous review of password management policies and credential storage mechanisms. The fact that approximately 75,000 Fortinet firewalls have been compromised indicates that the exposed credentials were likely weak, reused, or stored in an insecure manner. From a privacy perspective, the exposure of administrative credentials on devices used by government and private sector organizations raises serious concerns regarding the potential exfiltration of sensitive data. If attackers gain control over VPN gateways and firewalls, they can potentially intercept communications, access databases, and steal Personally Identifiable Information (PII) or classified data.

Open Questions

The campaign's global reach, impacting organizations in 194 countries, underscores the borderless nature of modern cyber threats. The use of compromised credentials implies that attackers may have harvested these credentials from third-party breaches or through phishing campaigns targeting administrators. This highlights the importance of identity verification and the need for multi-factor authentication (MFA) to mitigate the risk of credential stuffing attacks. Without robust identity controls, the exposure of a single set of credentials can have cascading effects across an organization's entire digital ecosystem, leading to severe security and privacy breaches.

Verification Checklist

To ensure the security posture of Fortinet devices is not compromised by the vulnerabilities highlighted in the FortiBleed reports, the following verification steps are recommended:

Environment Checklist

  • Review Credential Exposure: Audit administrator accounts to identify and reset any passwords that may have been exposed in third-party data breaches or known credential dumps.
  • Apply Security Patches: Ensure all Fortinet devices are running the latest version of FortiOS. Specifically, verify that administrator accounts are configured to use PBKDF2 as the hash function, as mandated in Fortinet's Technical Tip for v7.2.11 and later.
  • Network Segmentation: Restrict internet-accessible Fortinet devices to only necessary services and ports to minimize the attack surface.
  • Monitor for Anomalies: Implement logging and monitoring solutions to detect unusual administrative activity, such as login attempts from geographically distant locations or unexpected configuration changes.
  • Disable Unused Accounts: Conduct an inventory of all administrator accounts and disable or remove any that are no longer required.

Verification Statement

This article is based on reports and alerts provided by CISA and third-party security researchers. It has not been lab-tested. Readers must independently verify the specific configuration requirements, patch levels, and remediation steps outlined above against their specific Fortinet device models and firmware versions before deploying changes to production environments.

Verification Before Production Use

This article was not lab-tested. Verify the current vendor documentation, licensing and rollout conditions, and the behavior in a non-production environment before relying on it operationally.

// source record

Sources

  1. https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure www.cisa.gov ยท checked 19 June 2026