Futureweb

Security

What the FortiBleed advisory names

On October 6, 2026, the FBI and the Secret Service warned that FortiBleed is still hitting internet-facing FortiGate firewalls and SSL VPNs. The impact they name is lockout.

The short version

An ongoing credential-compromise campaign against internet-facing FortiGate firewalls and SSL VPN gateways. The FBI and Secret Service say some organizations are locked out when accounts are changed or deleted.

What happened

On October 6, 2026, the FBI and the U.S. Secret Service published joint cybersecurity advisory JCSA-20261006-01, titled around FortiBleed operations against exposed systems and reports of lockouts. The advisory says FortiBleed is an active, global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. It says attackers are continuing to use previously obtained credentials, and that organizations may be locked out if accounts are disabled or passwords are changed. BleepingComputer and The Register reported the advisory on October 7. The page filing the document, not a procedure, is Futureweb.

What the advisory says is in scope

The products are internet-facing FortiGate firewalls and SSL VPN gateways. The advisory says the campaign has been observed as an initial entry point for ransomware affiliates. It cites SOCRadar for a figure of more than 86,644 compromised devices across 194 countries. That count is SOCRadar's, as the advisory prints it, not an FBI census this page is re-adding. The intended audience line says the advisory applies across critical-infrastructure sectors and is written for defensive analysts and security leadership. The desk is Security.

What lockout means here

The advisory says some victims may be locked out of their Fortinet devices if the actor deletes an original account or changes its password. It says new accounts may be created during the intrusion, and that deleting existing accounts can block the organization from the device. That is an impact: the legitimate administrators cannot get in. This page does not describe how credentials were collected, stored, or cracked, and it does not list indicators. A reader who wants those details has the advisory itself. An earlier brief on how this desk files an advisory is the advisory is the story.

Why it matters on this desk

The check is a named advisory, a date, two agencies, a product class, and a lockout. Operators of internet-facing FortiGate firewalls and SSL VPN gateways are the people the document is about. A different October bulletin, the NetScaler advisory filed earlier on this desk, is a different product and a different document. It is the NetScaler bulletin.

What the advisory asks, without a command list

The advisory's key actions, in its own summary, are to restrict external management of the devices, to terminate administrative and VPN sessions and reset those credentials, and to require phishing-resistant multifactor authentication on remote access and administrative accounts. This page names those categories because they are the document's own heading. It does not print configuration commands, and it does not rank a reader's network. What a CVE identifier is, which this advisory page is not substituting for a reading of the PDF, is what a CVE identifier is.

What the October 7 reports add

BleepingComputer and The Register reported that the campaign was ongoing and that lockouts of FortiGate VPN administrators were part of the story. They are the check that the October 6 PDF was not a single-desk reading. This page does not adopt either outlet's reconstruction of the campaign's tools. The primary text remains the FBI and Secret Service PDF. The outlets confirm the date, the name FortiBleed, and the lockout.

What to watch next

A later advisory that names a fixed software version, or a vendor bulletin that says a specific release closes the exposure, would add a version sentence this page does not yet have. A revision of the SOCRadar device count would replace that citation. Another outlet repeating the lockout headline would not. The October 6 document is the record.

What this page leaves in the PDF

Indicators, file names, and the campaign's internal steps stay in the advisory. Repeating them would turn a news brief into a procedure. The facts that belong here are the publisher, the date, the identifier JCSA-20261006-01, the product class, the lockout, the ransomware-affiliate entry point as the advisory states it, and the SOCRadar figure as a citation. A hardware question about a preorder announced the next day is unrelated and sits on Hardware.

What stays an advisory

What stays specific is a joint FBI and Secret Service advisory on October 6, 2026, about an ongoing credential-compromise campaign against internet-facing FortiGate firewalls and SSL VPN gateways, with lockouts when accounts are removed or passwords are changed. It is not a patch note with a version. It is not a how-to. BleepingComputer and The Register reported it the next day. The count of devices stays SOCRadar's count, inside the advisory's sentence. The document is marked TLP:CLEAR, which the advisory says recipients may share without restriction. Sharing the existence of the warning is not the same as reprinting indicators. This brief does the first and refuses the second. The identifier to ask for, if a reader wants the PDF, is JCSA-20261006-01, published October 6, 2026, by the FBI and the Secret Service. No Fortinet version number is being added on top of that identifier. BleepingComputer's October 7 story and The Register's October 7 story are the two newsroom accounts. They confirm the advisory was public the next day. They are not a second technical appendix, and this page does not turn them into one. The lockout, the product class, and the date are the sentences worth filing on this desk.

Sources

The reports this brief is filing. Futureweb did not republish them.

  1. FBI and U.S. Secret Service, JCSA-20261006-01 (October 6, 2026)
  2. BleepingComputer, FortiBleed lockouts
  3. The Register, FortiBleed advisory

Questions

Who published the FortiBleed advisory, and on what date?

The FBI and the U.S. Secret Service, on October 6, 2026. The document is joint cybersecurity advisory JCSA-20261006-01.

Which products does the FortiBleed advisory say are targeted?

Internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The advisory calls FortiBleed an active, global credential-compromise campaign.

What lockout does the FortiBleed advisory describe?

Organizations may be locked out if accounts are disabled or passwords are changed. The advisory says some victims are locked out when original accounts are deleted or their passwords are changed.

Does this page reproduce the FortiBleed attack steps?

No. It files the date, the agencies, the product class, the lockout, and the advisory's statement that the campaign has been an initial entry point for ransomware affiliates.

Whose device count does the FortiBleed advisory cite?

SOCRadar's. The advisory says SOCRadar verified more than 86,644 compromised devices across 194 countries. That figure is the advisory's citation, not a count this paper made.