Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

FBI Warns FortiBleed Campaign Still Active, Compromising Over 86,000 FortiGate Firewalls

The FBI alerts that the FortiBleed (CVE‑2022‑42475) vulnerability continues to be weaponized, with more than 86,000 FortiGate firewalls reported compromised. The episode underscores the need for continuous vulnerability‑management evidence to satisfy audit and control‑assurance requirements.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 hackread.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
hackread.com

FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices

What Happened — The FBI’s latest advisory confirms that threat actors are still exploiting the FortiBleed vulnerability (CVE‑2022‑42475) in Fortinet FortiGate firewalls.  SOCRadar’s telemetry shows more than 86,644 devices across 194 organizations have been compromised, with attackers using an unauthenticated remote‑code‑execution path to install persistent back‑doors.

Why It Matters for Trust & Control Assurance

  • Continuous vulnerability‑management programs must surface unpatched CVEs in real time and produce auditable evidence of remediation.
  • Demonstrable, time‑stamped patch‑deployment records satisfy the control objective of “Vulnerability Management” that underpins many frameworks (e.g., NIST CSF Identify, ISO 27001 A.12.6).
  • A robust Trust Center can aggregate patch‑status data across firewalls, giving auditors a defensible trail of due‑diligence.

Who Is Affected – Telecommunications, financial services, healthcare, and any sector that relies on FortiGate perimeter appliances for network security.

Recommended Actions

  • Inventory all FortiGate devices and verify firmware versions against Fortinet’s patch list.
  • Apply the latest FortiOS updates (≥ 7.2.4 or later) that address CVE‑2022‑42475.
  • Enable automated vulnerability scanning and integrate findings into your continuous control‑monitoring platform.
  • Capture patch‑deployment logs as evidence for audit readiness.

Technical Notes – The exploit works over TCP 443, bypasses authentication, and allows arbitrary code execution on the firewall’s management plane. No specific data set was disclosed, but compromised devices can be leveraged to intercept traffic or exfiltrate data.

Source: HackRead – FBI Warns FortiBleed Campaign Still Active

📰 Original Source
https://hackread.com/fbi-fortibleed-campaign-active-fortigate-devices/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →