TL;DR
FortiBleed has compromised approximately 74,000 Fortinet devices globally across 194 countries, making credential resets and MFA enforcement the single most urgent task this weekend. CISA added at least a dozen new entries to its Known Exploited Vulnerabilities catalog this week, including critical flaws in Splunk Enterprise and Joomla. If you run Fortinet firewalls, Splunk, or any Joomla-based site, block out Saturday morning for patches — Monday is too late.
1. FortiBleed: 74,000 Fortinet Devices Compromised — Are Yours Among Them?
CISA issued an alert on June 18 urging all Fortinet customers to immediately harden FortiGate firewalls and SSL VPN gateways after reports emerged that malicious actors have been targeting internet-accessible Fortinet devices using leaked credentials. The campaign, dubbed "FortiBleed" by researchers, has exposed credentials for approximately 74,000 devices — roughly half of all internet-facing Fortinet firewalls globally, spanning 194 countries.
Why it matters to Australian SMBs: Fortinet FortiGate firewalls are one of the most common perimeter devices used by Australian small and mid-size businesses. If your organisation has a Fortinet firewall with an internet-facing management interface or SSL VPN portal, you should assume your credentials may be in the leaked dataset. This is not a theoretical risk — attackers are actively using these credentials to log in.
Do this today:
- Terminate all active SSL VPN and admin sessions on every FortiGate device
- Reset all Fortinet VPN and administrative passwords — especially on internet-facing systems
- Enforce PBKDF2 password hashing and remove legacy weak hashes (per Fortinet's guidance for FortiOS v7.2.11+)
- Enable phishing-resistant MFA on all remote access and admin accounts
- Restrict management interfaces to trusted internal networks only — never expose admin to the public internet
- Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, or unauthorised config changes
2. New CVEs Added to CISA's Known Exploited Vulnerabilities Catalog
CISA added multiple new entries to its Known Exploited Vulnerabilities (KEV) catalog this week — these are vulnerabilities confirmed to be actively exploited in the wild, not theoretical risks. The catalog now stands at 1,623 entries total.
Top entries added this week:
CVE-2026-20253 (Splunk Enterprise) — Missing authentication for a critical function allows unauthenticated users to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. Date added: June 18. CISA remediation due date: June 21 (this Sunday). If you run Splunk Enterprise, this is a same-day fix.
CVE-2026-48907 (Widget Factory Joomla Content Editor) — Improper access control allows unauthenticated users to upload and execute arbitrary PHP code via creation of new editor profiles. Date added: June 16. CISA due date was June 19 — if you haven't patched yet, you're already past the deadline. Any Joomla site using the Widget Factory Content Editor plugin needs immediate patching or removal of the plugin.
Multiple additional KEV additions throughout the week — CISA posted at least 10 separate "Adds Known Exploited Vulnerability" alerts, indicating sustained threat actor activity across diverse vendor ecosystems.
Why it matters: The KEV catalog is the gold standard for patch prioritisation. If a CVE is on this list, attackers are already using it. Australian SMBs should subscribe to KEV catalog updates and treat any matching software in their environment as an emergency patch — not a scheduled maintenance item.
3. Google Chrome: Batch of High-Severity Vulnerabilities
The National Vulnerability Database published a cluster of high-severity Chrome CVEs (CVE-2026-9990 through CVE-2026-9999) affecting versions prior to 148.0.7778.216. These include:
- Sandbox escape vulnerabilities via use-after-free bugs in Input, Core, Views, and Network components
- Out-of-bounds read in WebRTC allowing information disclosure from process memory
- Integer overflow in Skia enabling potential sandbox escape from a compromised renderer
- Use-after-free in WebXR and WebAppInstalls enabling code execution
Why it matters: Chrome is the dominant browser in Australian workplaces. While many of these require a compromised renderer process as a prerequisite, the chain from a malicious web page to full sandbox escape is shorter than most assume. Ensure all Chrome installations are updated to 148.0.7778.216 or later across every device — including personal devices used for work.
4. Regulatory Watch: Australian Privacy Act and Notifiable Data Breach Obligations
With FortiBleed affecting organisations across 194 countries, Australian businesses need to be thinking about their obligations under the Notifiable Data Breach (NDB) scheme. If a Fortinet credential leak leads to unauthorised access to personal information held by your organisation, and that access is likely to result in serious harm to individuals, you have a legal obligation to assess and notify.
Key obligations under the Privacy Act:
- Assess within 30 days of becoming aware of a suspected breach
- Notify the OAIC and affected individuals if the breach is likely to result in serious harm
- Document every step of your assessment — failure to assess is itself a compliance failure
- Apply the Essential Eight — the ACSC's baseline mitigation strategies remain the most cited control set in Australian breach investigations
Practical step this weekend: If you run Fortinet devices, document your credential reset and log review process now. If you later discover unauthorised access occurred, having a timestamped record of your response actions strengthens your position with the OAIC.
5. Threat Actor Activity: Active Exploitation Pace Remains High
The volume of KEV catalog additions this week — at least 10 separate alerts — signals sustained, broad-spectrum exploitation by threat actors. The FortiBleed campaign alone demonstrates that credential leak databases are being operationalised at scale. Threat actors are not waiting for zero-days; they are weaponising known vulnerabilities and leaked credentials faster than organisations can patch.
Key indicators this week:
- Credential-based attacks on network edge devices (FortiBleed)
- Web application plugin exploitation (Joomla Content Editor)
- Enterprise SIEM platform targeting (Splunk Enterprise)
- Browser-based exploit chains (Chrome sandbox escapes)
The pattern is clear: attackers are hitting every layer — perimeter, application, SIEM, endpoint. No single control is sufficient.
ISO 27001 SMB Starter Pack — $147
Threat intelligence is one thing — having the policies and controls to respond is another. Get the complete ISO 27001 starter kit for SMBs.
Get the Starter Pack →Patches to Apply This Weekend
| Priority | CVE / Issue | Software | Deadline |
|---|---|---|---|
| Critical | FortiBleed credential leak | Fortinet FortiGate / FortiOS | Immediately |
| Critical | CVE-2026-20253 | Splunk Enterprise | June 21 (Sunday) |
| Critical | CVE-2026-48907 | Joomla Widget Factory Content Editor | Past due — patch now |
| High | CVE-2026-9990–9999 | Google Chrome < 148.0.7778.216 | Update all devices |
| High | All June 2026 KEV additions | Check CISA KEV catalog | Per due dates |
Threat Level This Week: ELEVATED
Active exploitation of Fortinet credentials plus 10+ new KEV entries in a single week indicates a high-tempo threat environment. Australian SMBs with Fortinet perimeter devices are at direct risk. Treat this weekend as an active maintenance window, not a break.
What to Watch Next Week
- FortiBleed fallout: Expect follow-on advisories as researchers analyse which organisations were actively breached using leaked credentials. Australian-specific impact assessments may emerge from the ACSC.
- Additional KEV additions: The pace of 10+ additions per week suggests more are coming. Monitor the CISA KEV catalog RSS feed.
- Privacy Act reform: Watch for any movement on the Australian Government's Privacy Act review — proposed changes to penalties and the small business exemption could shift SMB obligations significantly.
- Chrome exploit chains: Researchers may publish proof-of-concept code for the Chrome sandbox escape cluster, raising the risk of in-the-wild exploitation.
FAQ
Q: How do I know if my Fortinet device is affected by FortiBleed? Check whether your FortiGate firewall or SSL VPN gateway has an internet-facing management interface or VPN portal. If it does, assume exposure. CISA's alert recommends checking the credential leak databases referenced in their advisory (SOCRadar, Hudson Rock, Arctic Wolf) to determine if your device is listed. Regardless of whether you find your device, reset all credentials and enable MFA.
Q: We're a small business — do we really need to worry about Splunk and Joomla CVEs? Yes. Splunk Enterprise is used by many mid-size Australian organisations for log management and security monitoring. If compromised, attackers can blind your security visibility. Joomla remains one of the most common CMS platforms for Australian small business websites. The Widget Factory plugin vulnerability allows unauthenticated PHP code execution — which means full website takeover. If you're not sure whether you use these, audit your software inventory this weekend.
Q: What are my obligations under the Notifiable Data Breach scheme if FortiBleed affected us? If unauthorised access to personal information occurred and is likely to cause serious harm, you must notify the OAIC and affected individuals as soon as practicable. The 30-day assessment clock starts when you become aware of the suspected breach — not when you confirm it. Document your credential reset, log review, and any indicators of unauthorised access immediately.
Q: We don't have a dedicated IT security team. What's the minimum we should do this weekend? Reset all Fortinet passwords, enable MFA on all VPN and admin accounts, restrict management interfaces to internal networks, update Chrome on all devices, and check the CISA KEV catalog against your software inventory. If you run Splunk or Joomla, patch or disable the affected components. That covers 80% of this week's risk.
Conclusion
This week's threat landscape demands action, not awareness. FortiBleed alone puts every Australian SMB with a Fortinet firewall at direct risk of credential-based compromise, and the cascade of new KEV catalog entries means threat actors have a widening toolkit to work with. Block out Saturday morning: reset your Fortinet credentials, patch Splunk and Joomla if you run them, update Chrome everywhere, and document every action you take in case you need to demonstrate compliance to the OAIC later.
Security is our religion, privacy is our drive. Don't let Monday morning be the first time you think about this week's threats.
Visit consult.lil.business for a free cybersecurity assessment.
References
- CISA Alert: CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
- CISA Known Exploited Vulnerabilities Catalog
- NIST National Vulnerability Database — Recent CVE Publications
- Office of the Australian Information Commissioner — Notifiable Data Breaches Scheme
- Australian Cyber Security Centre — Essential Eight Maturity Model