FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins
Exploitation of Fortinet FortiGate SSL VPN vulnerabilities continues to disrupt administrative access globally

Key Takeaways
- The FBI warns that FortiBleed attacks are ongoing and targeting exposed FortiGate firewalls.
- Exploitation locks out legitimate administrators and may enable unauthorized access or service disruption.
- Fortinet has released patches and advisories; immediate application is recommended.
- Organizations with exposed SSL VPN gateways are at highest risk.
- Verification of patch status via official Fortinet advisories is essential.
Quick answers
- What happened?
- The FBI has issued a private industry notification warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways. The exploitation locks out legitimate administrators and may facilitate unauthorized access or service disruption. Fortinet has released advisories and patches, but many systems remain unpatched and exposed.
- Which products are affected?
- FortiGate
- What should defenders do?
- Apply the latest FortiOS firmware updates as released by Fortinet. Follow Fortinet's security advisory guidance to disable or restrict SSL VPN access where possible. Monitor FBI and Fortinet advisories for updates. Restrict network access to management interfaces. Ensure all FortiGate devices are running supported and patched firmware versions.
The Federal Bureau of Investigation (FBI) has alerted organizations that FortiBleed attacks remain active in the wild. The threat targets Fortinet FortiGate firewalls, specifically those with SSL VPN gateways exposed to the internet. By exploiting the FortiBleed vulnerability, actors can cause a denial-of-service condition that locks out legitimate administrators from the affected devices. The FBI's warning indicates that the exploitation is ongoing and that victims include organizations globally with exposed FortiGate infrastructure. Compromise may allow unauthorized access or disruption of VPN services, impacting business operations. Fortinet has released security advisories and firmware patches to address the vulnerability. The agency recommends that administrators apply the latest updates and follow Fortinet's mitigation guidance immediately. The full technical details of the exploit and the extent of compromise are still emerging, and organizations are urged to verify patch availability via official Fortinet security advisories.
Security Details
FortiBleed exploitation targets Fortinet FortiGate firewalls and SSL VPN gateways, causing denial-of-service conditions that lock out legitimate administrators. The vulnerability allows remote exploitation to disrupt administrative access and potentially enable unauthorized access or service disruption.
Affected products
FortiGate
Mitigation
Apply the latest FortiOS firmware updates as released by Fortinet. Follow Fortinet's security advisory guidance to disable or restrict SSL VPN access where possible. Monitor FBI and Fortinet advisories for updates. Restrict network access to management interfaces. Ensure all FortiGate devices are running supported and patched firmware versions.
Sources
BleepingComputer
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
Oct 7, 2026 · 21:28
Original link
Related Security News

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Google reported on October 6, 2026, that threat actors compromised the registry operations of three country-code top-level domains (.gh, .sl, and .as) and obtained unauthorized HTTPS certificates for several Google domains. Google confirmed its own infrastructure was not breached, but any domain ending in these ccTLDs was placed at risk of impersonation. With fraudulent certificates, attackers could execute man-in-the-middle or phishing attacks against end-users visiting affected domains.




