If your organization is locked out of a FortiGate after a security incident, treat the lockout as a possible compromise—not just a forgotten password. First contain active access and preserve logs, backups, and diagnostic data. Then determine whether any authorized administrator can still log in. The right recovery path depends on the FortiGate model, whether it is a physical appliance or VM, its FortiOS version, and whether a trustworthy backup is available.
Contain the incident and preserve evidence first
Coordinate with your incident-response lead or qualified security staff before making changes that could disrupt service or affect evidence. Fortinet advises preserving available logs, backups, and diagnostic outputs before reformatting a device or reloading firmware. See Fortinet’s compromised-host guidance.
- Record the FortiGate model and FortiOS version if you can do so safely.
- Preserve available logs, backups, and diagnostic information in a location accessible to the response team.
- Note when the lockout began, what access methods fail, and any observed configuration or account changes.
- Coordinate any session termination or credential changes with the response lead so evidence collection and business continuity are considered.
For suspected credential compromise, Fortinet recommends terminating active administrator and VPN sessions and resetting Fortinet VPN and administrative passwords. The order and timing should be coordinated with incident response; immediately changing access can affect operations and evidence collection. Fortinet’s June 19, 2026 analysis of reported FortiGate credential compromise describes credential harvesting that involved reuse of previously compromised credentials and brute-force attempts, and characterizes the activity as not involving a new Fortinet vulnerability. That report does not establish the cause of every FortiGate lockout.
Work out which administrative access still works
Check only authorized access paths: the management GUI, SSH, console, FortiManager if your organization uses it, and another authorized administrator’s account. A failed GUI login alone does not prove that every administrator is locked out; the management method may be blocked or the problem may be limited to one account.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- If another authorized administrator can log in: use supported account-management options for the installed FortiOS version. Review unfamiliar administrator accounts and configuration changes, then rotate credentials from a trusted administrative system.
- If a different authorized management path works: use it to investigate why the usual path failed, while preserving relevant logs and configuration evidence.
- If no authorized administrative path works: do not try a generic bypass or assume a password-reset procedure applies. Identify the exact model and FortiOS release, then consult the matching Fortinet documentation and Fortinet support before destructive recovery.
Administrator behavior and requirements vary by FortiOS version. For example, Fortinet’s FortiOS 8.0.0 administrator-password documentation says password policy is enabled and enforced by default starting in FortiOS 7.6.5. Check the documentation for the release actually installed rather than relying on a procedure from another version.
Choose recovery based on access, device, and backup state
| Situation | Practical next step | Key risk or dependency |
|---|---|---|
| Another authorized administrator can log in | Investigate accounts and changes, then use supported account management to restore access and rotate credentials. | Preserve evidence and work from a trusted administrative system. |
| All administrator access is lost on a physical appliance | Consult the exact model and release instructions and Fortinet support. Fortinet’s documented lost-password route may require physical access and a TFTP firmware reload. | The reload resets configuration; it is not a harmless password change. |
| All administrator access is lost on a VM | Consult the exact VM and FortiOS documentation and Fortinet support before recovery. | Fortinet says lost-password procedures can differ between physical appliances and VMs. |
| A saved configuration may be available | Verify it is trusted and appropriate for the device and firmware before using it to restore service. | Restoration may depend on firmware compatibility and the encryption password used for the backup. |
| Backup integrity or incident scope is uncertain | Preserve the backup and have the response team assess it before restoring. | A potentially tampered backup can reintroduce unwanted accounts or configuration. |
Fortinet’s FortiOS 7.4.5 backup and reset documentation describes configuration backup and restore options, including local or USB storage and, in supported contexts, management-server or CLI paths. It also documents execute factoryreset as a reset to factory defaults and execute factoryreset2 as a reset that preserves management access under the conditions described there. These commands have significant effects; neither should be treated as a first-line password fix.
Rank #2
Know what the maintainer-account change means
Do not depend on the old maintainer-account route without checking the installed release. Fortinet says the maintainer account previously used after a hard reboot was removed beginning with FortiOS 7.2.4. Its maintainer-account change documentation says its lost-password guidance requires physical access and a TFTP firmware reload, which resets the configuration. The procedure can differ for physical appliances and VMs.
If recovery requires a console connection, verify the exact appliance model and its connection requirements before sourcing a cable or attempting access; Fortinet’s guidance does not establish one universal cable, interface, or terminal setting.
Recommended Free Tools
After access returns, check more than the password
Regaining administrator access restores control, but it does not establish that the device or connected network is safe. Fortinet’s June 19, 2026 campaign analysis recommends the following checks:
- Terminate remaining active administrator and VPN sessions.
- Reset administrative and VPN passwords, and enable multifactor authentication where supported.
- Compare firewall and VPN configuration with a known-good baseline; investigate unexpected administrator access and unauthorized changes in the logs.
- Reduce management exposure so administrative interfaces are not reachable from places that do not need access.
- Based on incident findings, rotate other secrets that may have been exposed through the device or its configuration, such as VPN shared secrets or identity-service credentials.
- Check Fortinet’s current security guidance and the official Fortinet PSIRT advisory list, then select a supported FortiOS release and upgrade path for the exact model.
If the internal network may also have been compromised, Fortinet advises contacting Fortinet support. Do not treat a successful firewall login as proof that other systems, accounts, or network segments are unaffected.
Rank #4
Put the reported credential exposure in context
CISA’s alert, revised June 22, 2026, describes leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. That figure refers to the specific reported credential-exposure campaign; it is not a general estimate of how many FortiGate devices are compromised. Read the CISA alert alongside Fortinet’s campaign-specific analysis when assessing whether the reported activity is relevant to your incident.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →

