Vulnerability  ·  2026-06-20

FortiBleed Credential Harvesting Campaign — 86,644 Firewalls Compromised

VulnerabilityHigh impactGlobal
On June 18, 2026, CISA and researchers disclosed that 86,644 Fortinet devices had been compromised with working credentials exposed online. The threat actors built a verified database of credentials for major enterprises and government agencies, likely gathered through prior breaches or configuration file exfiltration.
Compromised firewalls are the entry point to internal networks hosting AI/ML infrastructure. Once inside the perimeter, attackers can compromise model servers, vector databases, and agentic systems. This is a widespread campaign affecting mission-critical infrastructure.
Attackers systematically mass-scanned the internet for Fortinet remote login endpoints, then sprayed a curated database of leaked FortiGate passwords against discovered devices. Successful credential compromise gave attackers persistent access to enterprise perimeter networks, enabling lateral movement to internal AI/ML infrastructure.
Fortinet FortiGate firewalls and SSL VPN gateways; no specific CVE but exploits credential reuse and weak password policies
Immediate actions: Change all FortiGate admin credentials to unique, strong passwords. Enable MFA on all remote access. Audit logs for suspicious login activity. CISA alerts at: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
Sources
CISA Alert: Hardening Fortinet DevicesThe Hacker News: FortiBleed CampaignSecurityWeek: FortiBleed Campaign Coverage
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →