Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

FortiBleed remained an active credential-compromise campaign targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, according to an October 6, 2026 joint advisory from the FBI and U.S. Secret Service. Separately, an October 9 forecast anticipated a busy Microsoft update release and other vendor updates for October Patch Tuesday; those predictions should not be treated as confirmed fixes until vendors publish release notes.

FortiBleed is a credential-compromise campaign, not a newly disclosed Fortinet flaw

The FBI and U.S. Secret Service described FortiBleed as an active global campaign using credentials against exposed Fortinet firewalls and SSL VPN gateways. The advisory says attackers continued scanning internet-facing devices with credentials obtained earlier. It does not describe a newly disclosed Fortinet software vulnerability as the campaign’s entry point. Read the October 6 joint advisory.

The agencies cite a SOCRadar estimate of more than 86,644 compromised devices across 194 countries. That is an attributed count of compromised devices, not a live count of all exposed Fortinet equipment. CISA’s earlier June 18 bulletin cited approximately 74,000 devices associated with leaked credentials; it is a separate, earlier measurement and should not be combined with SOCRadar’s later figure. CISA’s June bulletin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the access chain works

The advisory describes an industrialized sequence: attackers scan exposed portals, test credentials from old breaches and infostealer logs through credential stuffing and password spraying, and extract password hashes from compromised devices for offline cracking using a distributed GPU cluster. They then create administrator accounts, enumerate Active Directory, expand access, and package working VPN access for sale to other actors.

#1 Best Overall

The advisory names INC/Lynx and Payload among ransomware affiliates receiving access at the time it was published. That roster is time-sensitive, not a permanent or exhaustive list. The agencies warn that victims may be locked out if attackers delete or alter legitimate accounts, and that the access chain has supplied ransomware affiliates.

What Fortinet gateway defenders should do

Treat possible exposure as an identity and appliance-integrity incident, not merely a patching task. CISA’s June guidance and the October joint advisory point to layered steps; a password reset or software update by itself does not establish that an appliance is clean.

Contain access and strengthen authentication

  • Terminate active VPN and administrative sessions, then reset affected credentials. Include credentials that may have been reused or exposed in older breaches.
  • Enable phishing-resistant multifactor authentication for remote access and administrative accounts. A FIDO2 security key may be one implementation, but confirm compatibility with your identity provider, FortiGate configuration, and organizational policy; it does not prove an appliance is uncompromised.
  • Make firewall administration inaccessible from the public internet wherever operationally feasible.

Check appliance and account integrity

  • Review administrator and API identities for unauthorized additions or changes, and compare appliance configuration with a known-good baseline.
  • Confirm that password hashes use PBKDF2 credential storage, as CISA recommends.
  • Review firewall, VPN, authentication, and domain-controller logs for suspicious access, account changes, and lateral movement. Scope internal activity before eviction actions so that remediation does not overlook access elsewhere.

Plan for recovery and cautious blocking

Because attackers may change or delete legitimate accounts, verify recovery paths and preserve the ability to regain administrative access. Use current telemetry to validate indicators before blocking them: CISA cautions that hostile IP infrastructure can be reassigned, so an indicator may no longer reliably identify the same actor or activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the October 2026 Patch Tuesday forecast expected

In a forecast published October 9, Ivanti Senior Product Manager Todd Schell expected Microsoft to address a high number of vulnerabilities across most of its portfolio, though he anticipated a lower volume than September. He also expected Adobe product updates, the usual Chrome for desktop 156 update, and at least one update among Firefox and Thunderbird. He did not expect another Apple update soon after September 29. These are pre-release predictions, not confirmed October release contents. Read Schell’s forecast.

Schell reported that September 2026 updates addressed 973 CVEs across Microsoft’s portfolio, with two known exploited and none publicly disclosed. This is Schell’s reported September tally, not an independently attributed Microsoft statement.

Anticipated lifecycle and issue-related items

  • The forecast expected final updates for Windows 11 version 24H2 Home and Professional.
  • It anticipated extended security updates for Windows Server 2012 and 2012 R2, and the end of extended security update support for Exchange Server 2016 and 2019.
  • It expected fixes for Excel cut-and-paste and File History/Windows Backup issues introduced by September updates.

Confirm each item against Microsoft’s actual release notices before treating it as delivered or using it to make deployment decisions. For prioritization, distinguish forecast from confirmed release status, check whether a product version remains supported, and verify current exploitation and disclosure information.

Legacy Office support deserves a separate review

Schell highlighted confusion around Office 2016 and Office 2019. Microsoft continued issuing security updates for those products after their October 14, 2025 end-of-support date under a stated discretionary exception. Separately, an update intended to refresh Microsoft 365 applications reportedly removed or deactivated some Office 2016/2019 installations, after which Microsoft paused it. Organizations should review their installed versions, update channels, and migration plans rather than assume that all Office installations behave alike.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Other security developments in the weekly roundup

The October 11 roundup also pointed to Microsoft’s out-of-band Exchange Server update CVE-2026-96940 and a CISA Known Exploited Vulnerabilities catalog addition for Citrix NetScaler CVE-2026-88779. These are separate developments, not part of Schell’s October Patch Tuesday prediction. Read the October 11 roundup.

What to prioritize this week

  1. If you operate an internet-facing FortiGate or SSL VPN: assess exposure and possible credential reuse, terminate sessions, reset credentials, and review account and configuration integrity.
  2. If access may have been compromised: scope activity across identity systems and internal networks, confirm recovery access, and investigate before treating a reset or patch as complete remediation.
  3. If you manage monthly updates: use the October 9 forecast for preparation only; confirm actual vendor notices, supported-version applicability, and exploitation status before prioritizing specific October patches.
  4. If you still run Office 2016 or 2019: check the installed version and update channel, and make a deliberate migration plan in light of the support exception and reported installation disruption.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.