FortiBleed - Analysis of Reported Credential Compromise of FortiGate Devices

Published: 22/06/2026 03:01 AM Category: Advisory CVE: CVE-2025-59718 & CVE-2025-59719
CRITICAL SEVERITY

Mitigation Advice

Fortinet has identified the potentially compromised systems, and we are proactively contacting impacted customers. To defend against this malicious cyber activity, Fortinet recommends that customers with impacted FortiGate appliances to immediately:

  • Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.
  • Implement MFA on all administrator and VPN user accounts.
  • Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support PBKDF2 hashing of administrator credentials. Follow the guidance to remove older legacy password settings via set login-lockout-upon-weaker-encryption.
  • Validate configuration. Review firewall and VPN users and other configuration for unauthorized changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognized accounts, such as β€œforticloud, fortiuser, fortinet-support, fortinet-tech-support,” etc.
  • Check your logs. Look for unexpected administrator access from unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.
  • Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best).

Reference: https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices