Analysis of Reported Credential Compromise of FortiGate Devices

2026-07-23T08:52:23Z11b7f4a63ee84be69d6d546292d4973ab4eae1af65dcfc75be2d03e4263142d2
CVE-2023-27997FG-IR-19-283FG-IR-23-097FortiBleedFortiGateFortiOSFortinetIoCN-day exploitationPSIRTSSO abuseVPN credentialscredential compromisedata leakpatchingpost-exploitationthreat actor

What happened

Collection of Fortinet PSIRT blog analyses describing active exploitation and post‑exploitation activity against FortiGate/FortiOS devices. Topics include a reported credential compromise campaign dubbed “FortiBleed”, single sign‑on (SSO) abuse, observed abuse of advisory FG-IR-19-283, threat actor postings claiming stolen FortiGate configurations and VPN credentials, and exploitation of resolved N‑day vulnerabilities. Fortinet calls out active exploitation (including FG-IR-23-097 / CVE-2023-27997, rated Critical), provides investigation findings, IoCs, and mitigation/patching guidance to help

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
11b7f4a63ee84be69d6d546292d4973ab4eae1af65dcfc75be2d03e4263142d2
Enrichment time
2026-07-23T08:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.