Analysis of Reported Credential Compromise of FortiGate Devices

2026-06-20T08:52:25Ze6ca20ad72d17f71d13773bc55969b036f53fd4d3c167aa9504a612e53e43003
CVE-2023-27997FG-IR-19-283FG-IR-23-097FortiBleedFortiGateFortiOSFortinetIoCsN-day exploitationPSIRTSSL‑VPNSSO abuseVPN credentialsVolt Typhooncredential compromisepatchingpost-exploitationresponsible disclosurethreat actor activity

What happened

Collection of Fortinet PSIRT blog posts summarizing analysis and mitigation guidance for multiple incidents affecting FortiGate/FortiOS devices: reported credential compromise (referred to as “FortiBleed”), single sign-on (SSO) abuse, observed abuse of advisory FG-IR-19-283, exploitation of resolved N-day vulnerabilities, threat actor data postings claiming leaked VPN/configuration credentials, and a CVSS Critical SSL‑VPN advisory (FG-IR-23-097 / CVE-2023-27997). Fortinet publishes IoCs, post‑exploitation analysis, and emphasizes patching, configuration review, and responsible disclosure to降低r

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
e6ca20ad72d17f71d13773bc55969b036f53fd4d3c167aa9504a612e53e43003
Enrichment time
2026-06-20T08:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.