CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

2026-06-22T13:24:06Z723f01c23ae4e62fbb01c3cfac1bd4c5822be067755a45c6b673c1cd6953e479
AristaBOD-26-04CISAChromiumCiscoFortiBleedFortinetIvantiJoomlaKEVLiteSpeedMFAOracle PeopleSoftPBKDF2SSL VPNSplunkactive exploitationcredential exposurelog reviewmultifactor authenticationvulnerability management

What happened

CISA warns of widespread credential exposure affecting internet-accessible Fortinet devices (FortiGate firewalls and SSL VPN gateways) — ~74,000 devices — and urges immediate hardening: terminate active SSL VPN/administrative sessions, reset VPN and admin credentials, adopt PBKDF2 for admin password storage, review logs for lateral movement or unauthorized changes, and enforce phishing-resistant MFA on remote/admin access. Separately, CISA added multiple actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog (including Splunk, Joomla, Cisco SD‑WAN, LiteSpeed cP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
723f01c23ae4e62fbb01c3cfac1bd4c5822be067755a45c6b673c1cd6953e479
Enrichment time
2026-06-22T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.