No Bug. No Patch. Just Trust, Broken. Inside FortiBleed.
In mid-June 2026, security researcher Volodymyr Diachenko uncovered an exposed attacker directory containing what appeared to be valid login credentials for Fortinet FortiGate firewalls. Within days, researchers from Hudson Rock, SOCRadar, and Arctic Wolf confirmed the scale of the exposure.
Approximately 75,000 internet-facing FortiGate firewalls across 194 countries, along with credentials linked to more than 21,000 domains, were found in criminal databases ready to be sold or exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) quickly advised organisations to reset all Fortinet credentials and terminate every active session.
FortiBleed had no CVE. There was no software vulnerability to patch. The incident stemmed from stolen configuration files, credential reuse, and outdated password hashes that remained vulnerable because many administrators never logged in after security updates that improved password hashing.
Simply put, the firewalls themselves were not broken. The trust placed in them was.
This Is Not a Fortinet Problem. It Is a Perimeter Problem.
For nearly three decades, firewalls and VPN gateways have served as the front door to enterprise networks. The model was straightforward—secure the perimeter, encrypt the connection, and trust authenticated users.
FortiBleed is only the latest example showing why this approach is no longer enough. Previous leaks exposed hundreds of thousands of FortiGate VPN credentials, demonstrating that the same pattern continues to repeat on an even larger scale.
Nor is this unique to one vendor.
According to research from Zscaler:
- 56% of organisations experienced at least one VPN-related cyberattack in the past year.
- 91% are concerned that VPNs weaken their overall security posture.
Once a VPN accepts valid credentials, it often grants broad network access without continuously verifying whether the user, device, or session should still be trusted.
The Shift to SASE and Zero Trust Network Access
The cybersecurity industry has been moving away from traditional perimeter security towards Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA).
Gartner introduced the SASE framework in 2019, combining SD-WAN with cloud-delivered security services including:
- Zero Trust Network Access (ZTNA)
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB)
- Firewall-as-a-Service (FWaaS)
Gartner projects that by the end of 2026, 60% of new SD-WAN deployments will be delivered through a single-vendor SASE platform.
Unlike VPNs, ZTNA grants access only to specific applications, continuously validating user identity, device posture, and session behaviour throughout the connection.
Even if credentials are compromised, attackers cannot automatically move throughout the network.
Four Things Worth Fixing Before the Next FortiBleed
- Remove firewall and VPN management interfaces from direct internet exposure.
- Maintain strong credential hygiene and ensure password hashing is updated across all administrative accounts.
- Enforce Multi-Factor Authentication (MFA) for every privileged and remote access account.
- Adopt a phased migration from traditional VPNs to Zero Trust Network Access (ZTNA).
These actions significantly reduce the impact of stolen credentials and improve long-term cyber resilience.
The Bigger Lesson
FortiBleed is not fundamentally a Fortinet problem.
It is the consequence of relying on an architecture that assumes anything inside the perimeter can continue to be trusted indefinitely.
That assumption no longer reflects today's threat landscape.
How Galaxy Helps
Galaxy Office Automation helps enterprises modernise network security by moving beyond legacy perimeter architectures and implementing secure, cloud-delivered security models.
- Network Security Assessments
- Firewall & VPN Exposure Reviews
- SASE & Zero Trust Architecture
- Credential & Identity Hardening
- Secure Remote Access Modernisation
The question isn't whether your firewall vendor is secure.
The real question is whether your architecture still assumes trust lasts forever.
Start the conversation today:
https://www.goapl.com/contact
