Always excited to take on new projects and collaborate with innovative ideas.
+968 97716144
contact@aljulanda.info
https://aljulanda.info
Sultanate of Oman - Nizwa
A live campaign is exposing admin credentials on internet-facing FortiGate firewalls worldwide. Here is what happened, and the vendor-neutral lessons for anyone running edge devices in Oman and the Gulf.
If you run a FortiGate at the edge of your network, stop reading in a minute and go check your admin accounts. A live campaign called FortiBleed, chained with an authentication bypass tracked as CVE-2026-24858, has been quietly harvesting verified administrator credentials from internet-facing firewalls across 194 countries. This is not a theoretical CVE waiting for proof-of-concept code. Attackers were already inside devices, creating local admin accounts, before most people had heard the name.
I manage perimeter devices for multiple sites, and this one made me re-audit every edge box I touch. Below is what happened, why it matters far beyond Fortinet, and the concrete steps to take today.
CVE-2026-24858 is an authentication bypass with a CVSS score of 9.4, tied to FortiOS single sign-on (SSO). It does not only affect FortiGate — FortiManager and FortiAnalyzer are in scope too, which matters because those are the boxes you use to centrally manage everything else.
The scary part is the timeline. On 20 January 2026, customers reported attackers creating new local admin accounts despite running the then-latest FortiOS. In other words, being fully patched at the time was not enough — this was a zero-day. Two malicious FortiCloud accounts used in the attack were locked out on 22 January 2026. Fortinet then began patching.
The broader FortiBleed campaign exposed verified administrator credentials for internet-facing FortiGate firewalls across 194 countries. Related exploited CVEs in the same cluster include CVE-2025-59718 and CVE-2025-59719. Separately, Amazon Threat Intelligence observed a parallel campaign between 11 January and 18 February 2026 using AI-assisted tooling to enumerate exposed management ports and attempt credential-based access.
This got official attention fast. CISA added CVE-2026-24858 to its Known Exploited Vulnerabilities (KEV) catalog on 27 January 2026, with a federal remediation deadline of 30 January 2026. When CISA gives you three days, that tells you everything about how actively it is being exploited.
Fortinet patched the flaw in FortiOS v7.6.6. The recommended fixed branches are:
If you cannot patch immediately, the interim workaround is clear: disable FortiCloud SSO on any device where it is enabled. That closes the specific door being used while you schedule the upgrade.
Here is the part I want every network person in the Gulf to internalize. The specific bug is Fortinet's, but the underlying problem is universal: we put too much trust and too many credentials at the perimeter, and we expose the management plane to the internet.
A firewall admin panel reachable from any IP is a standing invitation. It does not matter if the box says Fortinet, MikroTik, Cisco, pfSense or SonicWall. A mistake I keep seeing on networks I get called in to fix is a management interface — HTTPS admin, SSH, or a VPN portal — listening on the WAN with nothing but a password in front of it. When a bypass like this lands, that password stops mattering entirely, and the attacker walks in and creates their own admin account.
The AI-assisted scanning campaign makes this worse. Exposed management ports are being enumerated at scale, automatically. If your device is findable, assume it has already been probed.
If you own FortiGate, FortiManager or FortiAnalyzer devices, do these in order:
Whatever brand sits at your edge, these principles apply. This is how I harden multi-branch networks so that a single vendor CVE does not become a company-wide breach.
The admin interface should never answer the open internet. On FortiGate, use local-in policies to limit admin access to trusted internal IP ranges. On other platforms the feature has a different name, but the principle is identical: management access from named source addresses only, ideally over an out-of-band or dedicated VPN.
Passwords alone are finished at the perimeter. Enforce phishing-resistant / FIDO2 MFA on every administrative login. Note the honest limitation: an authentication bypass like this one can sidestep MFA at the protocol level — but MFA still blocks the far more common credential-reuse and stolen-password attacks, so it stays mandatory.
Build credential rotation into your routine, and always include the AD/LDAP service accounts your edge devices bind with. In one deployment I worked on, the firewall password was solid but the LDAP bind account had not been changed in years — that account was the real prize.
Ship firewall, VPN and domain controller logs somewhere you actually read them. Off-hours admin logins and surprise admin accounts are the earliest signals you will get.
FortiBleed will fade from the headlines, but the lesson will not. Your firewall is only as strong as its most exposed management interface. Treat the edge as hostile territory, keep the management plane private, and rotate the credentials that a breach would hand over. Do that, and the next vendor CVE becomes a scheduled maintenance task instead of an emergency.
Image: DaveHabben — BY (via Openverse)
Your email address will not be published. Required fields are marked *
Cookie preferences