Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

6/24/2026 • Cyber Security

FortiBleed Explained: What Australian SMBs Need to Do Now

FortiBleed exposed working credentials for tens of thousands of Fortinet firewalls worldwide. Here's a plain-English explainer for Australian small businesses, plus a clear action list and the broader lesson for every brand.

What actually happened with FortiBleed

On 18 June 2026, the Australian Cyber Security Centre (ACSC) issued an alert about a widespread malicious campaign — nicknamed 'FortiBleed' by researchers — targeting internet-facing Fortinet FortiGate firewalls and SSL-VPN gateways. CISA in the United States and the NCSC in the United Kingdom published parallel advisories on the same threat.

The day before, on 17 June, security researchers (Hudson Rock / Volodymyr 'Bob' Diachenko) disclosed a validated database of working login credentials tied to roughly 73,932 Fortinet FortiGate devices — around 86,644 credentials — spread across 194 countries. That's estimated to be about half of all internet-reachable FortiGate devices. The campaign has reportedly been running since at least February 2026.

Here's the important bit, and we want to be fair about it: this is not a single shiny new vulnerability. It's a combination of older problems lining up.

Why this happened (and why it's not vendor-bashing to explain it)

Three things came together:

  • A credential-storage quirk during upgrades. Fortinet moved admin password storage to strong PBKDF2 hashing in FortiOS 7.2.11, 7.4.8 and 7.6.1. But when a device is upgraded from an older version, the existing admin passwords stay stored as weak SHA-256 hashes until that admin next logs in after the upgrade. So a patched-but-not-re-logged-in device can still be carrying old, weak hashes.
  • Reuse of stolen configuration data. Much of this traces back to older Fortinet bugs, especially CVE-2022-40684 — the October 2022 path-traversal authentication bypass — where attackers grabbed configuration data that's now being mined.
  • Offline cracking at scale. Attackers took those weak SHA-256 hashes and cracked them offline using GPU clusters.

To be clear and fair to Fortinet: they patched the underlying issues and introduced the stronger hashing. The exposure largely affects devices that were upgraded but never had an admin re-login to migrate the hash, that were never patched at all, or that expose management/VPN interfaces straight to the internet.

Why this matters to a small business

Your firewall and VPN gateway are the front door to everything — your files, your accounting system, your customer data, your remote staff. If someone has working admin or VPN credentials, they don't need to break a window. They walk in with a key.

For an Australian SMB, that can mean ransomware, data theft, mandatory breach notification, downtime and a very bad week. The good news is that the fix is concrete and achievable.

What to do right now if you run Fortinet

Follow the ACSC guidance. In order:

  1. Patch to FortiOS 7.2.11, 7.4.8 or 7.6.1 (or later). This is the baseline.
  2. Log in as each admin after upgrading. This is the step most people miss. Logging in forces the PBKDF2 migration so your admin passwords stop being stored as weak SHA-256 hashes. Patching alone is not enough.
  3. Rotate ALL admin and VPN credentials. Assume the old ones may be known. Change every admin password and every VPN account password.
  4. Stop exposing management interfaces to the internet. Your firewall's admin/management interface should never be reachable from the public internet. Lock it to your internal network or a VPN.
  5. Enforce multi-factor authentication (MFA) on all external interfaces. Especially SSL-VPN. MFA is what stops a cracked password from being enough on its own.
  6. Review your logs. Look for suspicious logins, logins from unexpected locations, and unexplained configuration changes since at least February 2026.

If you're unsure whether your devices were ever re-logged-in to migrate the hashes, treat them as exposed and rotate credentials anyway. It's cheap insurance.

The broader lesson — for every SMB, every brand

This isn't really a Fortinet story. It's an edge-device story, and the same principles apply no matter whose logo is on your firewall. As we covered in our earlier post on the biggest network security risks for Australian SMBs, edge devices are the number one target because they're internet-facing by design.

Whatever brand you run:

  • Patch promptly. Years-old firmware is an open invitation.
  • Never expose admin interfaces to the internet. Management belongs on the inside.
  • Always use MFA on any externally reachable login.
  • Practise least-privilege remote access. Give people only the access they actually need.
  • Rotate credentials regularly, and immediately after any incident or staff departure.

Fortinet, Cisco, anyone — these habits are what separate a near-miss from a breach.

How cloud-managed platforms reduce this class of risk

A big part of why FortiBleed grew so large is the gap between a fix existing and that fix actually being applied — patched-but-not-migrated devices, never-patched devices, and management ports left open. Cloud-managed platforms are designed to shrink exactly those gaps.

Using the Cisco Meraki MX as an example, a cloud-managed approach helps by:

  • Automatic, centrally-pushed firmware and security updates — so you're far less likely to be running years-old firmware without realising it.
  • Dashboard-level MFA and admin control — your administrator access lives in the cloud dashboard with MFA, not on a box hanging off the public internet.
  • No locally-exposed management interface to find and attack.
  • Central visibility of logins and configuration changes across all your sites in one place.

For smaller Australian sites and branches, that often looks like a Meraki MX67 or MX68, with the MX75 suiting busier offices that need more throughput or extra ports. All three are managed from the same dashboard.

We want to be honest here: no vendor is immune to vulnerabilities. Cisco and Meraki have had their own bugs, and they always will. This isn't a silver bullet. It's about reducing your attack surface and improving your patch and credential hygiene so that when the next industry-wide scramble happens, you're already in good shape rather than racing the clock.

The bottom line

FortiBleed is serious, but it's also very fixable. If you run Fortinet: patch, re-login each admin to migrate the hashes, rotate every credential, get management off the public internet, turn on MFA, and check your logs. If you run anything else, take it as a timely reminder to do the same hygiene checks on your own edge devices.

References

Talk to TYO Store

Not sure whether your firewall is exposed, or whether it's time for a change? TYO Store offers an edge-security review for Australian small and medium businesses — we'll help you check your patch status, lock down management access, and get MFA in place.

We specialise in Cisco Meraki (including the MX67, MX68 and MX75), and we're also happy to supply and advise on firewalls from other manufacturers. The right answer is the one that fits your business — so get in touch and we'll help you find it.

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.