Fortinet CVE-2026-24858 & FortiBleed, explained

Fortinet CVE-2026-24858 (an actively-exploited authentication bypass) and the FortiBleed mass credential leak hit at once, and they share one precondition: an internet-exposed management plane. The exploit fires before authentication, so it only works if the attacker can reach the interface. Veil doesn't patch FortiOS — apply the fix — but it removes the reachability, so the bypass has no management interface to reach.

Frequently asked questions

What is Fortinet CVE-2026-24858?

An actively-exploited authentication bypass in Fortinet's management/SSL-VPN interface. Because it's pre-authentication, it only requires that an attacker can reach the interface over the network — which is exactly the precondition cloaking removes.

What is FortiBleed?

A mass credential-leak campaign against internet-exposed Fortinet devices: attackers harvested configuration files and credentials from tens of thousands of appliances. The shared root cause with the auth bypass is an exposed management plane.

Does Veil replace patching my FortiGate?

No — patch FortiOS regardless. Veil removes the internet reachability of the management interface so a pre-auth exploit has nothing to connect to. Patch and cloak together.

Sources: CISA — Known Exploited Vulnerabilities Catalog · Penligent — firewall management plane as breach point

Back to the Veil blog