--===============8502993472336345030==
Content-Type: multipart/alternative; boundary="===============7935798216799210503=="
MIME-Version: 1.0
--===============7935798216799210503==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Cybersecurity Advisories for Cybersecurity and Infras= tructure Security Agency. This information has recently been updated and is=
now available.
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure =
[
https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-f= ortinet-devices-after-reports-credential-exposure ] 06/18/2026 5:20 PM EDT =
CISA is aware of global reports that malicious cyber actors have targeted i= nternet-accessible Fortinet devices across government and private sector or= ganizations using compromised credentials. This activity, referred to as Fo= rtiBleed, involves the exposure of leaked credentials associated with appro= ximately 74,000 Fortinet devices, including firewalls and virtual private n= etwork (VPN) gateways.
To defend against this malicious cyber activity, CISA urges impacted Fortin=
et customers with FortiGate appliances and associated secure sockets layer = (SSL) VPN gateways to immediately:
* Terminate sessions and reset credentials. Terminate all active SSL VPN = and administrative sessions. Reset all Fortinet VPN and administrative pass= words, especially on internet-facing systems, and enforce strong password p= olicies.=20
* Ensure secure credential storage. Confirm your organization=E2=80=99s u=
se of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to st= ore administrator credentials and remove weaker legacy hashes per Fortinet= =E2=80=99s guidance (see, Fortinet's Technical Tip: Enforcing PBKDF2 as has=
h function for administrator accounts in FortiOS v7.2.11 and later [ https:= //community.fortinet.com/fortigate-3/technical-tip-enforcing-pbkdf2-as-hash= -function-for-administrator-accounts-in-fortios-v7-2-11-and-later-220652 ])= .=20
* Review logs. Review firewall, VPN, authentication, and domain controlle=
r logs for lateral movement, unusual access, suspicious accounts, or unauth= orized configuration changes.=20
* Enable phishing-resistant multifactor authentication (MFA). Require phi= shing-resistant MFA [
https://www.cisa.gov/sites/default/files/publications= /fact-sheet-implementing-phishing-resistant-mfa-508c.pdf ] on all remote ac= cess and administrative accounts and ensure it is enforced on all external = gateways and administrative interfaces.=20
* Reduce the attack surface and lock down management access. Ensure the a= dministration of your firewall is inaccessible from the public internet; re= strict Fortinet management interfaces to trusted internal networks; and rem= ove or disable any unauthorized or unnecessary accounts.=20
See the following resources to determine your organization=E2=80=99s potent= ial impact and find additional guidance on the credentials compromised:
* Tech Times: Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: H= alf the Internet-Facing Fleet [
https://www.techtimes.com/articles/318599/2= 0260618/fortinet-fortigate-credential-leak-hits-73932-firewalls-half-intern= et-facing-fleet.htm ]=20
* SOCRadar: FortiBleed: The Compromise of 80,000+ Fortinet Firewalls [ ht= tps://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/ ]=20
* Hudson Rock: FortiBleed: 75,000 Fortinet Firewalls Compromised: Global = Enterprises Exposed =E2=80=93 Claim Your Ethical Disclosure [
https://www.h= udsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-e= nterprises-exposed-claim-your-ethical-disclosure ]=20
* Arctic Wolf: Active FortiBleed Campaign Impacting Fortinet Devices Acro=
ss 194 Countries [
https://arcticwolf.com/resources/blog/active-fortibleed-= campaign-impacting-fortinet-devices-across-194-countries/ ]=20
* Fortinet: Attacks at the Speed of AI [
https://www.fortinet.com/blog/in= dustry-trends/attacks-at-the-speed-of-ai ]=20
Disclaimer
The information in this report is being provided =E2=80=9Cas is=E2=80=9D fo=
r informational purposes only. CISA does not endorse any commercial entity,=
product, company, or service, including any entities, products, or service=
s linked within this document. Any reference to specific commercial entitie=
s, products, processes, or services by service mark, trademark, manufacture=
r, or otherwise, does not constitute or imply endorsement, recommendation, =
or favoring by CISA.
Please share your thoughts with us through this anonymous survey [
https://= cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliv= ery
https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-= fortinet-devices-after-reports-credential-exposure ]. We appreciate your fe= edback.
This product is provided subject to this=C2=A0Notification [
https://www.ci= sa.gov/notification ]=C2=A0and this=C2=A0Privacy & Use [
https://www.cisa.g= ov/privacy-policy ] policy.
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/41cb9c0 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using GovDelivery Communica= tions Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency=
=C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ =
https://subscriberhelp.granicus.com/ ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============7935798216799210503==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> CISA Urges Hardening Fortinet Devices After Reports of Credentia=
l Exposure
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Cybersecurity Advisories for Cybersecurity and I= nfrastructure Security Agency. This information has recently been updated a=
nd is now available.</p>
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/aler= ts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credentia= l-exposure" target=3D"_blank" title=3D"CISA Urges Hardening Fortinet Device=
s After Reports of Credential Exposure" rel=3D"noopener">CISA Urges Hardeni=
ng Fortinet Devices After Reports of Credential Exposure</a></div>
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">06/18/2026 5:20 PM EDT</div>
<div class=3D"l-page-section l-page-section--rich-text csaf-imported">
<div class=3D"l-constrain">
<div class=3D"l-page-section__content">
<p>CISA is aware of global reports that malicious cyber actors have targete=
d internet-accessible Fortinet devices across government and private sector=
organizations using compromised credentials. This activity, referred to as=
FortiBleed, involves the exposure of leaked credentials associated with ap= proximately 74,000 Fortinet devices, including firewalls and virtual privat=
e network (VPN) gateways.</p>
<p>To defend against this malicious cyber activity, CISA urges impacted For= tinet customers with FortiGate appliances and associated secure sockets lay=
er (SSL) VPN gateways to immediately:</p>
<li>Terminate sessions and reset credentials. Terminate all active SSL VPN = and administrative sessions. Reset all Fortinet VPN and administrative pass= words, especially on internet-facing systems, and enforce strong password p= olicies.</li>
<li>Ensure secure credential storage. Confirm your organization=E2=80=99s u=
se of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to st= ore administrator credentials and remove weaker legacy hashes per Fortinet= =E2=80=99s guidance (see, <a href=3D"
https://community.fortinet.com/fortiga= te-3/technical-tip-enforcing-pbkdf2-as-hash-function-for-administrator-acco= unts-in-fortios-v7-2-11-and-later-220652" target=3D"_blank" title=3D"Fortin= et's Technical Tip: Enforcing PBKDF2 as hash function for administrator acc= ounts in FortiOS v7.2.11" rel=3D"noopener">Fortinet's Technical Tip: Enforc= ing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 a=
nd later</a>).</li>
<li>Review logs. Review firewall, VPN, authentication, and domain controlle=
r logs for lateral movement, unusual access, suspicious accounts, or unauth= orized configuration changes.</li>
<li>Enable phishing-resistant multifactor authentication (MFA). <a href=3D"=
https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementi= ng-phishing-resistant-mfa-508c.pdf" target=3D"_blank" title=3D"Require phis= hing-resistant MFA" rel=3D"noopener">Require phishing-resistant MFA</a> on = all remote access and administrative accounts and ensure it is enforced on = all external gateways and administrative interfaces.</li>
<li>Reduce the attack surface and lock down management access. Ensure the a= dministration of your firewall is inaccessible from the public internet; re= strict Fortinet management interfaces to trusted internal networks; and rem= ove or disable any unauthorized or unnecessary accounts.</li>
</ol>
<p>See the following resources to determine your organization=E2=80=99s pot= ential impact and find additional guidance on the credentials compromised:<=
<li>Tech Times: <a href=3D"
https://www.techtimes.com/articles/318599/202606= 18/fortinet-fortigate-credential-leak-hits-73932-firewalls-half-internet-fa= cing-fleet.htm" target=3D"_blank" title=3D"Fortinet FortiGate Credential Le=
ak Hits 73,932 Firewalls: Half the Internet-Facing Fleet" rel=3D"noopener">= Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: Half the Internet= -Facing Fleet</a>
</li>
<li>SOCRadar: <a href=3D"
https://socradar.io/blog/fortibleed-fortinet-firew= alls-compromised/" target=3D"_blank" title=3D"FortiBleed: The Compromise of=
80,000+ Fortinet Firewalls" rel=3D"noopener">FortiBleed: The Compromise of=
80,000+ Fortinet Firewalls</a>
</li>
<li>Hudson Rock: <a href=3D"
https://www.hudsonrock.com/blog/fortibleed-7500= 0-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethi= cal-disclosure" target=3D"_blank" title=3D"FortiBleed: 75,000 Fortinet Fire= walls Compromised: Global Enterprises Exposed =E2=80=93 Claim Your Ethical = Disclosure" rel=3D"noopener">FortiBleed: 75,000 Fortinet Firewalls Compromi= sed: Global Enterprises Exposed =E2=80=93 Claim Your Ethical Disclosure</a> </li>
<li>Arctic Wolf: <a href=3D"
https://arcticwolf.com/resources/blog/active-fo= rtibleed-campaign-impacting-fortinet-devices-across-194-countries/" target= =3D"_blank" title=3D"Active FortiBleed Campaign Impacting Fortinet Devices = Across 194 Countries" rel=3D"noopener">Active FortiBleed Campaign Impacting=
Fortinet Devices Across 194 Countries</a>
</li>
<li>Fortinet: <a href=3D"
https://www.fortinet.com/blog/industry-trends/atta= cks-at-the-speed-of-ai" target=3D"_blank" title=3D"Attacks at the Speed of = AI" rel=3D"noopener">Attacks at the Speed of AI</a>
</li>
</ul>
<h3>Disclaimer</h3>
<p>The information in this report is being provided =E2=80=9Cas is=E2=80=9D=
for informational purposes only. CISA does not endorse any commercial enti= ty, product, company, or service, including any entities, products, or serv= ices linked within this document. Any reference to specific commercial enti= ties, products, processes, or services by service mark, trademark, manufact= urer, or otherwise, does not constitute or imply endorsement, recommendatio=
n, or favoring by CISA.</p>
<p>Please share your thoughts with us through this <a href=3D"
https://cisas= urvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliveryht= tps://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-forti= net-devices-after-reports-credential-exposure" target=3D"_blank" title=3D"a= nonymous survey" rel=3D"noopener">anonymous survey</a>. We appreciate your = feedback.</p>
<p>This product is provided subject to this=C2=A0<a href=3D"
https://www.cis= a.gov/notification" target=3D"_blank" title=3D"Follow link" rel=3D"noopener= ">Notification</a>=C2=A0and this=C2=A0<a href=3D"
https://www.cisa.gov/priva= cy-policy" target=3D"_blank" title=3D"Follow link" rel=3D"noopener">Privacy=
& Use</a> policy.</p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/41cb9c0" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using GovDelivery Com= munications Cloud, on behalf of: Cybersecurity and Infrastructure Security = Agency =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://subscriberhelp.granicu= s.com/" target=3D"_blank" rel=3D"noopener"><img src=3D"
https://content.govd= elivery.com/images/govd-logo-dark.png" border=3D"0" alt=3D"GovDelivery logo=
" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/0101019edca2caa8-f= c63c0b2-d212-43de-9f63-6c409dd71c32-000000/bTr3Btnlc7I-QrwSGfRu33L8IM-qFtx-= 9ZSn-TdVjmQ=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============7935798216799210503==--
--===============8502993472336345030==--