Back to advisories

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

FortiBleed campaign continues harvesting credentials from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Over 86,644 credentials have been compromised through exploitation of reused/leaked passwords and legacy storage mechanisms. Attackers use these credentials for lateral movement and data exfiltration.

CRITICALAdvisoryOct 08, 2026
Action required
Immediately audit all Fortinet FortiGate and SSL VPN gateway devices for exposed internet access. Reset all administrative and service account credentials on affected systems. Hunt for Go-based traffic interception tools and evidence of lateral movement from compromised Fortinet devices.
Affected products
FortinetFortiGateSSL VPN