Risk Identified from Leaked Credentials Affecting FortiGate and SSL VPN Systems

Risk Identified from Leaked Credentials Affecting FortiGate and SSL VPN Systems

Information:

   Fortinet FortiGate is a Next-Generation Firewall (NGFW) used by organizations to protect and control network traffic, as well as detect and prevent cyber threats from external sources. Meanwhile, SSL VPN is a remote access feature available on FortiGate that enables users to securely access internal organizational resources over the Internet.

Incident:

  FortiBleed is a global cyberattack campaign targeting Fortinet FortiGate devices and SSL VPN services. Rather than exploiting a new zero-day vulnerability, the campaign leverages credentials obtained from previous security incidents, such as Infostealer malware infections, data breaches, and credential leaks. These stolen credentials are then used to attempt authentication against internet-facing FortiGate devices and SSL VPN portals.

  According to published reports, more than 86,644 credential records and access-related data entries associated with FortiGate devices have been identified across 194 countries worldwide. Organizations that continue to use compromised credentials or have not implemented Multi-Factor Authentication (MFA) may be at risk of unauthorized access to their FortiGate management interfaces or SSL VPN services.

Impact:

-  Threat actors may use compromised SSL VPN accounts to gain unauthorized access to the 

   organization's internal network and further expand access to other systems within the environment.

- Customer data, financial information, and other sensitive organizational data may be accessed, exfiltrated, or disclosed without authorization.

-If threat actors obtain administrative privileges, they may modify system configurations, disable security alerts, or alter security policies, potentially weakening the organization's security posture.

-Data breaches may negatively impact the organization's reputation and could result in non-compliance with regulatory requirements, such as PDPA.

    Verification Method:

       Organizations can check for potential credential exposure using the following platforms:

        -  https://socradar.io/free-tools

        -  https://www.hudsonrock.com/

Recommendation:

  - Change passwords for all FortiGate administrators and SSL VPN users, and review any password

          reuse across other systems.

  - Enable Multi-Factor Authentication (MFA) for all accounts, especially administrator and

          SSL VPN accounts.

  - Restrict management access to authorized IP addresses only, or require administrators

          to connect through a VPN before accessing the management interface.

        - If any organizational credentials are found in leaked datasets, assume potential compromise

          and initiate an immediate security investigation.

        - Check for exposed credentials using the official services provided by SOCRadar and Hudson Rock.

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References :

          -  https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/?utm_source=chatgpt.com

           -  https://www.itpro.com/security/passwords-nicked-for-nearly-74-000-fortinet-devices?utm_source=chatgpt.com

           -  https://www.reuters.com/world/fortinet-says-credential-harvesting-campaign-is-targeting-its-firewalls-vpn-2026-06-17/?utm_source=chatgpt.com

           -  https://www.hudsonrock.com/ 

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-12019

11/6/2026

12/6/2026

Google Chrome on Linux and ChromeOS prior to 149.0.7827.115

Heap Buffer Overflow

8.3

Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

Upgrade Chrome to version 149.0.7827.115 or later

https://app.opencve.io/cve/CVE-2026-12019

 

2

CVE-2026-39808

14/4/2026

11/6/2026

FortiSandbox 4.4

command injection

9.1

An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

Upgrade FortiSandbox to version 4.4.9 or higher

https://fortiguard.fortinet.com/psirt/FG-IR-26-100

3

CVE-2026-11933

12/6/2026

12/6/2026

MongoDB Server's server-side JavaScript engine

use-after-free

8.7

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.

Upgrade MongoDB to a version that includes the fix for SERVER-128125.

https://app.opencve.io/cve/CVE-2026-11933

 4

CVE-2026-25700

10/6/2026

10/6/2026

Apache Answer: through 2.0.0.

AdminToken

7.2

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired.

upgrade to version 2.0.1

https://app.opencve.io/cve/CVE-2026-25700

5

CVE-2026-54228

13/6/2026

13/6/2026

Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8

time-of-check time-of-use (TOCTOU)

7.8

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.

Disable or remove ABRT if it is not required.On RHEL 8 systems where ABRT is installed

https://app.opencve.io/cve/CVE-2026-54228

 

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

15/06/2026​

Remote Code Execution, Privilege Escalation, Persistence​

Palo Alto Networks has issued a warning about an active exploitation of vulnerabilities in its PAN-OS firewall operating system. Attackers are scanning for devices with open management interfaces on the internet and using these vulnerabilities to gain control. Analysis indicates that a successful attack could allow hackers to execute commands on the firewall, escalate privileges, install a web shell, and use the firewall as a gateway to infiltrate the organization's internal systems. Several organizations have already reported these attacks. Palo Alto recommends that organizations immediately update security patches, disable internet access to the management interface, restrict access to only essential IPs, and review logs for signs of intrusion.​

  • Update PAN-OS immediately to the version that fixes the vulnerability.​
  • Do not open the Management Interface to direct internet access.​
  • Enable Multi-Factor Authentication (MFA).

Ref: https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html

 

        

23 June 2026

Viewed 95 time

Engine by shopup.com