Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Fortinet’s initial assessment, published June 19, 2026, describes a reported credential-harvesting campaign using credentials exposed in earlier incidents and brute-force attempts against devices with weak passwords and no multifactor authentication (MFA). Fortinet says it is not a newly discovered FortiGate vulnerability. CISA separately reported that approximately 74,000 Fortinet devices were associated with exposed credentials; that figure is not a count of confirmed intrusions or victims. Administrators should immediately end active sessions, reset FortiGate administrator and VPN passwords, enforce phishing-resistant MFA, remove public management access, and investigate logs and configuration changes.

Is this a new Fortinet vulnerability?

Not according to Fortinet’s initial analysis. In its June 19, 2026 report, Fortinet describes the activity as reuse of credentials from earlier incidents combined with brute-force attempts against systems with weak password hygiene and no MFA. Carl Windsor of Fortinet wrote: “This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory.” Read the vendor’s full assessment at Fortinet’s June 19 analysis.

That distinction matters. A stolen or guessed administrator password can give an attacker control without exploiting a newly disclosed software defect. You still need to treat evidence of unauthorized access as a potential compromise, but do not describe the reported campaign as proof of a new FortiOS flaw.

What the “74,000 devices” figure means

CISA’s June 18, 2026 notice says exposed credentials were associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. CISA does not present that number as a verified total of successful compromises. It indicates devices linked to exposed credentials. See CISA’s advisory for the agency’s wording and recommendations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Fortinet FortiGate-70G Firewall for Branch and Small Offices with 10 Gigabit Ethernet RJ45 Ports (FG-70G)
  • Next-generation firewall for small office and branch security with NGFW, IPS, and web filtering built in
  • Secure SD-WAN improves cloud and SaaS performance while maintaining consistent security policy
  • Deep visibility with SSL inspection and application control to identify and govern encrypted traffic
  • Simple deployment and centralized management via FortiGate Cloud or FortiManager
  • Seamless integration with FortiSwitch and FortiAP for a unified, secure wired and wireless network

Fortinet says it identified potentially compromised systems and was proactively contacting impacted customers. The notices do not provide a public, definitive list that every organization can use to determine whether its appliance is included. Assume exposure is possible if your device or its credentials were internet-accessible, reused elsewhere, or protected without MFA.

Immediate containment steps

  1. Terminate active sessions. End all current FortiGate administrative sessions and VPN sessions. This removes already-authenticated access that may survive a password change.
  2. Reset credentials. Change passwords for FortiGate administrators and VPN users, prioritizing internet-facing systems. Do not reuse passwords from another service, and reset any identity-provider, directory, or service account that shared a credential with FortiGate.
  3. Enforce strong password policy. Require long, unique passwords and remove dormant administrator and VPN accounts. Document who approved each remaining privileged account.
  4. Preserve evidence. Export relevant firewall, VPN, authentication, and domain-controller logs before retention limits overwrite them. Record the current configuration and software version.

If your organization finds unauthorized changes or other indicators, stop treating the appliance as merely at risk: follow Fortinet’s recovery guidance and involve qualified incident-response personnel. Fortinet advises customers who believe their internal network may have been compromised to contact Fortinet support.

Rank #2
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Close the access paths attackers target

Require phishing-resistant MFA

Enable MFA for every FortiGate administrator and remote-access account. CISA specifically recommends phishing-resistant MFA for administrative and remote-access accounts and says it should be enforced at external gateways and administrative interfaces. A FIDO2 security key can be one possible authenticator, but verify that it works with your identity provider and FortiGate authentication design before deployment; CISA does not endorse a particular brand or model.

Remove public management exposure

Firewall administration should not be reachable from the public internet. Fortinet describes trusted hosts, a local-in policy, or removing internet administration as progressively stronger controls. CISA likewise recommends restricting management interfaces to trusted internal networks. Keep remote administration behind a controlled access path, log it, and limit the source networks and accounts that can use it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Fortinet FortiGate-70G Firewall for Branch and Small Offices with 3-Year FortiGuard AI-Powered Unified Threat Protection Services (FG-70G-BDL-950-36)
  • Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.

Check credential hashing and FortiOS support

Fortinet says current releases in the 7.4, 7.6, or 8.0 branches support PBKDF2 hashing for administrator credentials. CISA also advises confirming PBKDF2 and removing weaker legacy hashes. These are branch-level statements, not model-specific upgrade instructions.

Before changing firmware, check Fortinet’s current release and PSIRT guidance for the exact appliance model, installed version, and configuration. Confirm that the target release is supported for that hardware and that you have a tested backup and rollback plan. Do not select an upgrade solely because it has a 7.4, 7.6, or 8.0 label.

Rank #4
Fortinet FortiGate-70G Firewall for Branch and Small Offices with 1-Year FortiGuard AI-Powered Unified Threat Protection Services (FG-70G-BDL-950-12)
  • Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.

Investigate for unauthorized access or movement

Review identities and sessions

  • Look for administrator logins from unfamiliar IP addresses, countries, or time periods.
  • Identify unexpected VPN users, password resets, newly created accounts, and disabled or re-enabled users.
  • Check for unrecognized account names, including examples Fortinet lists such as forticloud, fortiuser, fortinet-support, and fortinet-tech-support.
  • Correlate FortiGate events with identity-provider, directory, and domain-controller logs.

Compare configuration with a known-good baseline

Review administrative settings, firewall policies, VPN configuration, routing, DNS, logging, and local-in rules. Compare the running configuration with a trusted backup or documented baseline. Pay particular attention to new administrators, altered authentication settings, changed tunnel endpoints, unexpected port forwards, and disabled logging.

Look for lateral movement

Search authentication and domain-controller records for use of accounts connected to the FortiGate. If Active Directory or LDAP is integrated, Fortinet says to treat the linked account as compromised, monitor where it is used, and investigate additional account creation or movement through the network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
FortiGate-60F Firewall Appliance - 10 Gigabit Ethernet RJ45 Ports, Includes DMZ, WAN & Internal Ports (Appliance Only, No Subscription) (FG-60F)
  • Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
  • Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
  • Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
  • Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
  • Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decision checklist for administrators

Check What to verify Action if the answer is unfavorable
Internet exposure Is administration or VPN access exposed externally? Remove public administration; restrict access to trusted networks and controlled gateways.
MFA Are all administrator and remote-access accounts protected by phishing-resistant MFA? Enforce MFA and verify the authentication integration.
Credential storage Are administrator credentials using PBKDF2 rather than weaker legacy hashes? Follow supported FortiOS guidance for the exact appliance and remove weaker settings.
Software support Is the installed FortiOS release supported for this model and deployment? Check current Fortinet release and PSIRT information before upgrading.
Evidence of compromise Do logs or configuration show unknown access, accounts, or changes? Treat the device as compromised, preserve evidence, begin recovery, and contact Fortinet support.

When to escalate

Escalate immediately when you find unauthorized configuration changes, unknown privileged accounts, unexplained VPN activity, suspicious directory use, or signs that the internal network was accessed. Isolate affected systems as your incident-response plan requires, preserve logs and configuration snapshots, and coordinate with Fortinet support. A qualified incident-response provider may be appropriate when the investigation extends beyond the firewall into identity systems or domain controllers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.