The FBI and Secret Service have warned that the FortiBleed campaign remains active, with threat actors locking out admins on Fortinet FortiGate firewalls across the globe.
The FBI and Secret Service have issued a fresh advisory warning that the FortiBleed exploit is still active, allowing threat actors to lock out administrators on Fortinet FortiGate firewalls worldwide.
What is FortiBleed?
FortiBleed is a vulnerability that targets the management interface of FortiGate devices, enabling attackers to bypass authentication and gain full control of the firewall configuration. Once compromised, the malicious actor can reset admin passwords, disable security policies, and effectively cripple network defenses.
Recent FBI and Secret Service Advisory
In a joint advisory released earlier this month, the FBI and the U.S. Secret Service warned that the campaign remains “highly active” and that compromised firewalls have been observed across multiple continents. The agencies emphasized that the threat actors are leveraging publicly available tools to automate the exploitation process, making it easier for less sophisticated groups to launch attacks.
The advisory also noted that the attackers are not only targeting large enterprises but also small and medium‑sized businesses that may lack dedicated security staff. Organizations that fail to apply the latest Fortinet patches are at greatest risk of being locked out of their own networks.
Mitigation Steps for Administrators
Fortinet recommends that all administrators immediately verify they are running firmware version 7.4.5 or later, which includes the patch for CVE‑2026‑XXXXX that addresses the FortiBleed flaw. Additionally, they advise:
- Review and update all admin passwords with strong, unique credentials.
- Enable multi‑factor authentication (MFA) on all management accounts.
- Restrict management access to trusted IP ranges using firewall policies.
- Monitor logs for repeated failed login attempts or unusual configuration changes.
If a firewall appears to be compromised, the advisory urges administrators to disconnect the device from the network, perform a forensic analysis, and restore from a known‑good backup before bringing it back online.
Industry Response
Security analysts have praised the rapid coordination between federal law‑enforcement agencies and Fortinet, noting that the joint warning helps raise awareness before further damage occurs. Some experts, however, caution that the sheer number of vulnerable devices in the wild could mean the campaign persists for months despite the patch rollout.
Organizations should treat this as a critical priority and verify that all FortiGate appliances are fully patched, as the window for exploitation remains open.
For detailed guidance, administrators can consult Fortinet’s official security advisory and the FBI’s public notice.