Short answer: Fortinet’s initial assessment, published June 19, 2026, describes a reported credential-harvesting campaign using credentials exposed in earlier incidents and brute-force attempts against devices with weak passwords and no multifactor authentication (MFA). Fortinet says it is not a newly discovered FortiGate vulnerability. CISA separately reported that approximately 74,000 Fortinet devices were associated with exposed credentials; that figure is not a count of confirmed intrusions or victims. Administrators should immediately end active sessions, reset FortiGate administrator and VPN passwords, enforce phishing-resistant MFA, remove public management access, and investigate logs and configuration changes.
Is this a new Fortinet vulnerability?
Not according to Fortinet’s initial analysis. In its June 19, 2026 report, Fortinet describes the activity as reuse of credentials from earlier incidents combined with brute-force attempts against systems with weak password hygiene and no MFA. Carl Windsor of Fortinet wrote: “This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.” Read the vendor’s full assessment at Fortinet’s June 19 analysis.
That distinction matters. A stolen or guessed administrator password can give an attacker control without exploiting a newly disclosed software defect. You still need to treat evidence of unauthorized access as a potential compromise, but do not describe the reported campaign as proof of a new FortiOS flaw.
What the “74,000 devices” figure means
CISA’s June 18, 2026 notice says exposed credentials were associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. CISA does not present that number as a verified total of successful compromises. It indicates devices linked to exposed credentials. See CISA’s advisory for the agency’s wording and recommendations.
#1 Best Overall
- Next-generation firewall for small office and branch security with NGFW, IPS, and web filtering built in
- Secure SD-WAN improves cloud and SaaS performance while maintaining consistent security policy
- Deep visibility with SSL inspection and application control to identify and govern encrypted traffic
- Simple deployment and centralized management via FortiGate Cloud or FortiManager
- Seamless integration with FortiSwitch and FortiAP for a unified, secure wired and wireless network
Fortinet says it identified potentially compromised systems and was proactively contacting impacted customers. The notices do not provide a public, definitive list that every organization can use to determine whether its appliance is included. Assume exposure is possible if your device or its credentials were internet-accessible, reused elsewhere, or protected without MFA.
Immediate containment steps
- Terminate active sessions. End all current FortiGate administrative sessions and VPN sessions. This removes already-authenticated access that may survive a password change.
- Reset credentials. Change passwords for FortiGate administrators and VPN users, prioritizing internet-facing systems. Do not reuse passwords from another service, and reset any identity-provider, directory, or service account that shared a credential with FortiGate.
- Enforce strong password policy. Require long, unique passwords and remove dormant administrator and VPN accounts. Document who approved each remaining privileged account.
- Preserve evidence. Export relevant firewall, VPN, authentication, and domain-controller logs before retention limits overwrite them. Record the current configuration and software version.
If your organization finds unauthorized changes or other indicators, stop treating the appliance as merely at risk: follow Fortinet’s recovery guidance and involve qualified incident-response personnel. Fortinet advises customers who believe their internal network may have been compromised to contact Fortinet support.
Rank #2
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Close the access paths attackers target
Require phishing-resistant MFA
Enable MFA for every FortiGate administrator and remote-access account. CISA specifically recommends phishing-resistant MFA for administrative and remote-access accounts and says it should be enforced at external gateways and administrative interfaces. A FIDO2 security key can be one possible authenticator, but verify that it works with your identity provider and FortiGate authentication design before deployment; CISA does not endorse a particular brand or model.
Remove public management exposure
Firewall administration should not be reachable from the public internet. Fortinet describes trusted hosts, a local-in policy, or removing internet administration as progressively stronger controls. CISA likewise recommends restricting management interfaces to trusted internal networks. Keep remote administration behind a controlled access path, log it, and limit the source networks and accounts that can use it.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.
Check credential hashing and FortiOS support
Fortinet says current releases in the 7.4, 7.6, or 8.0 branches support PBKDF2 hashing for administrator credentials. CISA also advises confirming PBKDF2 and removing weaker legacy hashes. These are branch-level statements, not model-specific upgrade instructions.
Before changing firmware, check Fortinet’s current release and PSIRT guidance for the exact appliance model, installed version, and configuration. Confirm that the target release is supported for that hardware and that you have a tested backup and rollback plan. Do not select an upgrade solely because it has a 7.4, 7.6, or 8.0 label.
Rank #4
- Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
- User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
- Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.
Investigate for unauthorized access or movement
Review identities and sessions
- Look for administrator logins from unfamiliar IP addresses, countries, or time periods.
- Identify unexpected VPN users, password resets, newly created accounts, and disabled or re-enabled users.
- Check for unrecognized account names, including examples Fortinet lists such as forticloud, fortiuser, fortinet-support, and fortinet-tech-support.
- Correlate FortiGate events with identity-provider, directory, and domain-controller logs.
Compare configuration with a known-good baseline
Review administrative settings, firewall policies, VPN configuration, routing, DNS, logging, and local-in rules. Compare the running configuration with a trusted backup or documented baseline. Pay particular attention to new administrators, altered authentication settings, changed tunnel endpoints, unexpected port forwards, and disabled logging.
Look for lateral movement
Search authentication and domain-controller records for use of accounts connected to the FortiGate. If Active Directory or LDAP is integrated, Fortinet says to treat the linked account as compromised, monitor where it is used, and investigate additional account creation or movement through the network.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
- Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
- Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
- Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
- Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
- Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.
Decision checklist for administrators
| Check | What to verify | Action if the answer is unfavorable |
|---|---|---|
| Internet exposure | Is administration or VPN access exposed externally? | Remove public administration; restrict access to trusted networks and controlled gateways. |
| MFA | Are all administrator and remote-access accounts protected by phishing-resistant MFA? | Enforce MFA and verify the authentication integration. |
| Credential storage | Are administrator credentials using PBKDF2 rather than weaker legacy hashes? | Follow supported FortiOS guidance for the exact appliance and remove weaker settings. |
| Software support | Is the installed FortiOS release supported for this model and deployment? | Check current Fortinet release and PSIRT information before upgrading. |
| Evidence of compromise | Do logs or configuration show unknown access, accounts, or changes? | Treat the device as compromised, preserve evidence, begin recovery, and contact Fortinet support. |
When to escalate
Escalate immediately when you find unauthorized configuration changes, unknown privileged accounts, unexplained VPN activity, suspicious directory use, or signs that the internal network was accessed. Isolate affected systems as your incident-response plan requires, preserve logs and configuration snapshots, and coordinate with Fortinet support. A qualified incident-response provider may be appropriate when the investigation extends beyond the firewall into identity systems or domain controllers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

