On 17 June 2026, security researchers published details of a dataset containing valid VPN credentials for 73,932 Fortinet FortiGate firewall and SSL VPN appliances. The dataset, now being referred to as FortiBleed, includes usernames, password hashes, and in some cases plaintext passwords, along with device IP addresses, serial numbers, and firmware versions for each affected device.

If your business uses Fortinet equipment for remote access or firewall management, you need to act now rather than later.

What Actually Happened

FortiBleed traces back to exploitation of CVE-2022-40684, a critical path traversal vulnerability in FortiOS that was assigned a CVSS score of 9.8. The flaw allowed unauthenticated attackers to read and modify configuration files, including administrator credentials, without logging in. Fortinet patched it in October 2022 and issued urgent advisories, but many organisations either applied the patch late or didn’t rotate their credentials after patching.

The result is a dataset of credentials that were harvested during the exploitation window and are potentially still valid today. Researchers estimate the database covers around 50% of all internet-reachable FortiGate devices across 194 countries.

To be clear: this is not a new vulnerability. The credential dump was made from past exploitation, not a fresh attack. But the credentials themselves may still be valid if they haven’t been changed since the original compromise — which is exactly the problem.

Why This Matters Even If You Patched in 2022

A lot of organisations patched CVE-2022-40684 promptly. The patch stops new exploitation. What it doesn’t do is invalidate credentials that were already captured before the patch was applied.

Think of it this way: if someone copied your house keys before you changed the locks, changing the locks doesn’t make the copy useless. The copy works until you change the locks again — or in this case, until you change the credentials.

Many businesses patched the vulnerability and assumed that was sufficient. It wasn’t, if credentials weren’t rotated immediately afterwards. And four years on, those original credentials may well still be in active use, especially on devices that haven’t had much admin attention since they were first configured.

What You Need to Do

Rotate Fortinet VPN and management credentials immediately. All of them: VPN user accounts, admin accounts, service accounts with access to the management interface. Don’t schedule this for next week.

Disable or restrict access to the management interface from the internet. FortiGate management consoles should not be reachable from the public internet under any normal circumstances. If yours is, that’s a separate and urgent problem — restrict it to internal networks or an out-of-band management network.

Enable multi-factor authentication for VPN access if it isn’t already in place. Credentials alone are no longer sufficient for VPN access, and this incident is a clear illustration of why.

Check your firmware version. If you’re running a FortiOS version that was vulnerable to CVE-2022-40684, you should upgrade regardless of whether you patched at the time — there have been further FortiOS vulnerabilities since 2022 that older firmware versions won’t address.

Review your logs for suspicious activity. Look particularly at authentication logs from 2022 to 2023, when CVE-2022-40684 was actively exploited. If you see any anomalous successful logins from unusual IP addresses during that period, treat it as a potential compromise and investigate further.

How to Check If Your Device Is in the Leak

Several security vendors, including BitSight and others, are offering checks against the FortiBleed dataset. You can cross-reference your FortiGate’s public IP address or serial number against published indicators. Your Fortinet partner or reseller should also be able to advise.

Even if your specific device isn’t in the published dataset, credential rotation is still the right action. You don’t know for certain what data exists that hasn’t been published.

For Businesses Using Managed IT or an MSP

If you have a managed IT provider or MSP handling your Fortinet equipment, contact them today and ask specifically: have Fortinet VPN credentials been rotated since October 2022? Has MFA been enabled for VPN access? Is the management interface restricted from the internet?

These are direct, answerable questions. If your provider isn’t sure or can’t confirm, that’s the starting point for an urgent conversation.

The Broader Point About VPN Credentials

VPN systems are high-value targets because they’re the front door to your network. A valid VPN credential gives an attacker remote access that looks like a legitimate employee working from home. Most VPN authentication attempts, legitimate or otherwise, don’t generate alerts — they’re expected traffic.

This is why credential rotation, MFA, and access logging for VPN systems aren’t optional security hygiene items. They’re the baseline for any network with internet-facing remote access, which in 2026 means effectively every small business.

Fortinet equipment is common in UK small businesses — it’s one of the two or three brands most frequently deployed by IT providers and resellers alongside Sophos and Cisco Meraki. If you have Fortinet kit and can’t immediately confirm your credentials have been rotated recently, assume they haven’t, and change them today.