Analysis of Reported Credential Compromise of FortiGate Devices

2026-06-20T20:52:22Z4962a868ac107b0b687b54b7f69f2f531f61e4e2d4809855c4edb275aca083ee
credential-compromisecve-2023-27997fg-ir-19-283fortibleedfortigatefortinetfortiosiocn-daypatchingpost-exploitationpsirtresponsible-disclosuresso-abusethreat-actorvolt-typhoonvpn-credentialsvulnerability-exploitation

What happened

Fortinet PSIRT blog posts provide multiple analyses of observed abuse and compromises affecting FortiGate/FortiOS devices, including reported credential compromise (referred to as “FortiBleed”), single sign‑on (SSO) abuse, and post‑exploitation techniques. Fortinet documents threat actor activity such as public postings claiming compromised device configurations and VPN credentials, observed exploitation of N‑day vulnerabilities (notably CVE-2023-27997) and abuse related to advisory FG-IR-19-283, and publishes IoCs and mitigation guidance to help customers confirm impact and remediate (patch/h

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
4962a868ac107b0b687b54b7f69f2f531f61e4e2d4809855c4edb275aca083ee
Enrichment time
2026-06-20T20:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Analysis of Reported Credential Compromise of FortiGate Devices · Baitaphish