Analysis of Reported Credential Compromise of FortiGate Devices
2026-07-23T08:52:23Z•11b7f4a63ee84be69d6d546292d4973ab4eae1af65dcfc75be2d03e4263142d2
CVE-2023-27997FG-IR-19-283FG-IR-23-097FortiBleedFortiGateFortiOSFortinetIoCN-day exploitationPSIRTSSO abuseVPN credentialscredential compromisedata leakpatchingpost-exploitationthreat actor
What happened
Collection of Fortinet PSIRT blog analyses describing active exploitation and post‑exploitation activity against FortiGate/FortiOS devices. Topics include a reported credential compromise campaign dubbed “FortiBleed”, single sign‑on (SSO) abuse, observed abuse of advisory FG-IR-19-283, threat actor postings claiming stolen FortiGate configurations and VPN credentials, and exploitation of resolved N‑day vulnerabilities. Fortinet calls out active exploitation (including FG-IR-23-097 / CVE-2023-27997, rated Critical), provides investigation findings, IoCs, and mitigation/patching guidance to help
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- 11b7f4a63ee84be69d6d546292d4973ab4eae1af65dcfc75be2d03e4263142d2
- Enrichment time
- 2026-07-23T08:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.