FortiBleed Credential Theft Campaign Marches On
The campaign is not the result of a compromise of Fortinet itself, but rather involves the attackers testing a custom list of known passwords for Fortinet devices.
All topics
The campaign is not the result of a compromise of Fortinet itself, but rather involves the attackers testing a custom list of known passwords for Fortinet devices.
The company published an advisory on Saturday and urged all customers who are running affected versions of the software to install the hotfix as quickly as possible. The bug affects versions 7.4.5 and 7.4.6 of FortiClient EMS.
Fortinet is rolling out updates for CVE-2026-24858, with fixes for some versions available as of Tuesday, and others in releases that are upcoming at an unspecified date.
This activity shares some similarities with a campaign that researchers at Arctic Wolf identified in December. That campaign started soon after Fortinet disclosed two authentication bypass flaws (CVE-2025-59718 and CVE-2025-59719).
That vulnerability (CVE-2025-64446) affects several versions of FortiWeb and CISA has added it to its Known Exploited Vulnerabilities catalog.