Government Advisory

Critical Alert: Fortinet Firewall and VPN Credentials Reportedly Exposed in Widespread Campaign

ACSC · 18 June 2026
Key Takeaway If your business uses Fortinet firewalls or VPN gateways, check vendor advisories immediately and reset device credentials as a precaution against this reported exposure.

The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has issued a critical alert regarding public reporting of a malicious campaign targeting Fortinet firewalls and VPN gateways. The campaign is reportedly linked to widespread exposure of credentials associated with these devices, which could allow attackers to gain unauthorised access to affected networks.

Fortinet devices are widely used by businesses of all sizes to secure network perimeters and enable remote access, making this an issue of concern for organisations across Australia, including small and medium businesses that rely on these products for VPN connectivity. If credentials have been exposed, attackers could potentially bypass authentication controls and gain a foothold inside a business's network without needing to exploit a new vulnerability.

The ACSC's alert underscores the importance of businesses staying informed about developments in this campaign and taking prompt action if they use affected Fortinet products. This includes reviewing vendor advisories, checking for signs of compromise, and resetting credentials where appropriate as a precaution.

Fortinet VPN Security Credential Exposure ACSC Alert Network Security

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.