Skip to content
Back to the blog
Vulnerabilities June 24, 2026

FortiBleed: 86,644 FortiGate firewalls compromised and CISA’s urgent alert

The US cybersecurity agency CISA has issued an urgent warning to all businesses using Fortinet FortiGate devices after the discovery of a massive campaign dubbed “FortiBleed”. Contrary to what many headlines suggest, this is not a new software flaw, but a large-scale credential theft and reuse operation. The attackers have compiled one of the largest known databases of access to Fortinet devices: as of 19 June 2026, 86,644 compromised firewalls have been counted, spread across 194 countries and more than 21,000 different domains. That figure is equivalent to around half of all Fortinet firewalls exposed to the internet.

The method combines several well-known techniques, but carried out on an industrial scale: testing passwords leaked in previous breaches, massive brute-force attacks and cracking stored password “hashes”. The underlying problem is twofold. On the one hand, a huge number of organisations never changed the factory accounts and passwords. On the other, many devices still store keys with an old encryption scheme instead of a stronger one, because during updates the old password remains unmigrated until the administrator logs in again. This turns vulnerable devices into a silent gateway into corporate networks.

Tip from Soporte Informático 360

If your company uses a Fortinet FortiGate firewall or VPN, act now: close active sessions, reset all passwords, delete or rename factory accounts, enable multi-factor authentication (MFA) and restrict administration access to trusted internal networks only.

Source: The Hacker News. Summary prepared by our team for informational purposes.

Do you think a device may be compromised?

We help you check it, clean it and protect it. Write to us with no obligation.

Get help