Analysis of Reported Credential Compromise of FortiGate Devices
2026-06-20T20:52:22Z•4962a868ac107b0b687b54b7f69f2f531f61e4e2d4809855c4edb275aca083ee
credential-compromisecve-2023-27997fg-ir-19-283fortibleedfortigatefortinetfortiosiocn-daypatchingpost-exploitationpsirtresponsible-disclosuresso-abusethreat-actorvolt-typhoonvpn-credentialsvulnerability-exploitation
What happened
Fortinet PSIRT blog posts provide multiple analyses of observed abuse and compromises affecting FortiGate/FortiOS devices, including reported credential compromise (referred to as “FortiBleed”), single sign‑on (SSO) abuse, and post‑exploitation techniques. Fortinet documents threat actor activity such as public postings claiming compromised device configurations and VPN credentials, observed exploitation of N‑day vulnerabilities (notably CVE-2023-27997) and abuse related to advisory FG-IR-19-283, and publishes IoCs and mitigation guidance to help customers confirm impact and remediate (patch/h
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- fortinet_blog
- Record identifier
- 4962a868ac107b0b687b54b7f69f2f531f61e4e2d4809855c4edb275aca083ee
- Enrichment time
- 2026-06-20T20:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.