ACSC warns of widespread credential-based attacks on FortiGate gateways
Australia's ACSC issued an advisory on 18 June 2026 about a widespread campaign against Fortinet firewalls and VPN gateways that relies on exposed credentials rather than a software vulnerability. No CVE or victim count was published; ZoomEye data shows 983,996 internet-facing FortiGate devices, 254,801 of them with 2048-bit RSA TLS certificates.
- ACSC: attacks on FortiGate use stolen credentials, with no CVE or version list
- ZoomEye counted 983,996 internet-facing FortiGate devices on 23 September 2026
- 254,801 of them present a 2048-bit RSA TLS certificate
- Recommended mitigations: rotate credentials, enforce MFA and restrict management interfaces
Read next
Security