86,644 Fortinet devices. One unauthenticated RCE

Russian-speaking threat actors already inside enterprise perimeters worldwide.
This is FortiBleed. An active campaign that has already breached tens of thousands of network appliances globally. CISA issued a federal emergency classification and gave agencies 72 hours to patch. Not a 30-day window. Not a maintenance cycle. 72 hours.
- CVE-2026-20253 CVSS CRITICAL — UNAUTHENTICATED REMOTE CODE EXECUTION ON FORTINET DEVICES.
No credentials. No user interaction. A crafted request hits an exposed FortiGate management interface, triggers a memory corruption flaw, and delivers full remote code execution on the appliance. The attacker controls your perimeter. They see your traffic. They pivot inbound at will.
If your management interface is internet-facing, you are a direct target. Not hypothetical. Active.
But the CVE is only half the story.
THE CREDENTIAL DATA EXPOSES THE REAL FAILURE.
Of the credentials extracted from breached devices: — 35% were generic admin accounts. Default or shared credentials that should never exist in a production environment. — 28.3% were built-in Fortinet system accounts never disabled or renamed after initial deployment.
63% of the breach surface was not a zero-day problem. It was a configuration problem. Attackers did not break in. They walked through doors left open on day one of deployment.
86,644 compromised devices. The majority of them did not need to be in that count.
HOW TO RESPOND NOW
PATCH CVE-2026-20253 IMMEDIATELY — Federal emergency classification. Deploy the patch now. If patching is not immediately possible, take it offline.
AUDIT EVERY ADMIN ACCOUNT — Pull every account on every FortiGate in your environment. Remove all generic admin accounts. Disable every built-in system account with no operational justification. No exceptions.
LOCK DOWN MANAGEMENT ACCESS — The FortiGate management plane must never be internet-facing. Segment it onto an out-of-band network. Apply strict ACLs. Confirm isolation with an external scan.
HUNT FOR LATERAL MOVEMENT — Assume exposed appliances were already accessed. Review logs for anomalous outbound connections, unexpected authentication events, and configuration changes you did not authorize.
ROTATE ALL PERIMETER CREDENTIALS — Every credential stored on or used to authenticate to an affected device must be rotated now. Assume those credentials are already in threat actor hands.
The campaign was still active as of June 19, 2026. 86,644 devices confirmed compromised.
The patch exists. The hardening checklist is not complex.
The question is whether your Fortinet appliances are already in that count — or whether you are about to find out.