The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is attacking Fortinet FortiGate firewalls and SSL VPN gateways around the world.
The operation that stole credentials has affected over 86,644 devices in 194 countries, putting organizations at great risk if they expose Fortinet management or remote-access services online.
FortiBleed is not described as a single newly disclosed Fortinet vulnerability. Instead, attackers reportedly abuse reused, leaked, or weak credentials to access FortiGate appliances.
FortiBleed Campaign Exploits
The exposed infrastructure reportedly showed an organized access-broker operation that scanned for publicly reachable FortiGate SSL VPN portals, tested stolen passwords, cracked password hashes, and verified accounts before selling working access to other cybercriminals.
The attackers allegedly used credential stuffing and password spraying to test credentials obtained from previous data leaks and infostealer logs.
FortiBleed MITRE ATT&CK Techniques :
| Tactic | Technique | MITRE ID |
|---|---|---|
| Reconnaissance | Active Scanning | T1595 |
| Initial Access | Exploit Public-Facing Application | T1190 |
| Credential Access | Password Spraying | T1110.003 |
| Credential Access | Credential Stuffing | T1110.004 |
| Credential Access | Credential Dumping | T1003 |
| Credential Access | Password Cracking | T1110.002 |
| Persistence | Create Local Account | T1136.001 |
| Defense Evasion / Initial Access | Valid Accounts | T1078 |
| Discovery | Account Discovery | T1087 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
| Impact | Account Access Removal | T1531 |
Organizations need to quickly check all Fortinet admin and VPN accounts, especially any unknown ones like forticloud-sync, fgtsecure, forti_support2, or Technical_support.
Security teams need to check for unusual REST API keys, changes in settings, strange login activity, and links to known bad systems mentioned in the advisory.
SonicWall
SonicWall has fixed four security flaws in its Secure Mobile Access (SMA) 1000 Series devices, including a serious server-side request forgery (SSRF) issue with the highest CVSS score of 10.0.
The company shared security advice SNWLID-2026-0017 on October 6, 2026. SonicWall announced that there is no proof that these four weaknesses are being used by attackers. Still, it urges affected customers to update to the corrected software. The updates apply to both physical and virtual SMA 6210, SMA 7210, and SMA 8200v devices.
Critical Pre-Authentication SSRF
The main issue, known as CVE-2026-102255, impacts the SMA1000 Appliance WorkPlace interface. It comes from an unplanned alternate access point that lets the device work as a forward proxy.
Additional Security Flaws
CVE-2026-102256 is a post-authentication command-injection vulnerability rated 7.8. Under specific conditions, an authenticated administrator could execute arbitrary operating-system commands, resulting in remote code execution. The advisory does not establish that this flaw can be chained with the critical SSRF issue.
CVE-2026-102257, rated 7.2, is a Zip Slip vulnerability in the Appliance Management Console (AMC). A specially crafted archive could cause files to be extracted outside the intended destination folder. SonicWall says this path-traversal issue can lead to remote code execution.
Affected Versions And Required Updates
Affected versions are 12.4.3-03526 and older, and 12.5.0-02952 and older. Customers should upgrade to platform-hotfix 12.4.3-03670 or newer, or 12.5.0-03082 or newer, based on their software branch. SonicWall offers the latest hotfix through MySonicWall and has no workaround for these problems. The latest fixes solve all four issues in both affected firmware versions.
SSL-VPN services on SonicWall firewalls and the SMA 100 Series are safe. This helps admins find the right devices without thinking all SonicWall VPN setups are at risk from this notice.
InfoSecBulletin Cybersecurity for mankind
