FortiBleed: admin passwords for ~86,000 Fortinet firewalls already leaked

Almost 86,000 Fortinet firewalls — about half of those exposed to the internet — already have their admin passwords leaked. The campaign is called FortiBleed and, unlike an ordinary vulnerability, no simple update fixes it.

Attackers pulled the configuration files off FortiGate appliances and cracked the passwords offline. The painful detail: over 60% of the compromised accounts were default „admin” accounts that were never renamed. With an admin password in hand, an attacker sees the whole network behind the firewall and can reach servers and domain accounts. CISA issued an alert urging teams to take management interfaces off the internet, rotate passwords, and enforce two-factor authentication.

A firewall is your company’s front door. If you don’t know who holds the key, it’s worth checking today — not after someone uses it.

  • Find out whether your company firewall is a FortiGate and whether the management panel or VPN portal are reachable from the internet — if so, restrict access to the internal network only.
  • Rotate all administrator and VPN passwords, especially the unchanged „admin” account, and turn on two-factor authentication.
  • Ask your IT partner to update FortiOS (7.2.11 / 7.4.8 / 7.6.1 or newer), log back in on each appliance, and review the logs for new accounts or unusual access.

Sources

This article was generated with AI assistance.

We check your firewall and its exposure

← All news