CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
2026-06-22T13:24:06Z•723f01c23ae4e62fbb01c3cfac1bd4c5822be067755a45c6b673c1cd6953e479
AristaBOD-26-04CISAChromiumCiscoFortiBleedFortinetIvantiJoomlaKEVLiteSpeedMFAOracle PeopleSoftPBKDF2SSL VPNSplunkactive exploitationcredential exposurelog reviewmultifactor authenticationvulnerability management
What happened
CISA warns of widespread credential exposure affecting internet-accessible Fortinet devices (FortiGate firewalls and SSL VPN gateways) — ~74,000 devices — and urges immediate hardening: terminate active SSL VPN/administrative sessions, reset VPN and admin credentials, adopt PBKDF2 for admin password storage, review logs for lateral movement or unauthorized changes, and enforce phishing-resistant MFA on remote/admin access. Separately, CISA added multiple actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog (including Splunk, Joomla, Cisco SD‑WAN, LiteSpeed cP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 723f01c23ae4e62fbb01c3cfac1bd4c5822be067755a45c6b673c1cd6953e479
- Enrichment time
- 2026-06-22T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.