Threat reportCampaignTL-2026-1469
Coordinated Scanning Campaign Against Fortinet SSL VPN and Palo Alto GlobalProtect Infrastructure Detected via GreyNoise Vendor CVE / Tag Spike Signals
Coordinated Scanning Campaign Against Fortinet SSL VPN and (TL-2026-1469) is a medium-severity campaign, first published 2026-01-25. It has no confirmed attribution, affects Fortinet FortiOS SSL-VPN (sslvpnd), maps to 12 MITRE ATT&CK techniques (T1046, T1078, T1090), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1469
- Threat ID
- TL-2026-1469
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- CAMPAIGN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, critical-infrastructure, enterprise, finance, technology
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Coordinated Scanning Campaign Against Fortinet SSL VPN and
Malware and tooling: GreyNoise tag: Cisco ASA Arbitrary File Retrieval Attempt, GreyNoise tag: Cisco ASA CVE-2020-3259 Information Disclosure Attempt, GreyNoise tag: Cisco ASA Scanner, GreyNoise tag: Fortinet SSL VPN Bruteforcer, GreyNoise tag: Palo Alto Networks Login Scanner
How Coordinated Scanning Campaign Against Fortinet SSL VPN and works
GreyNoise's new Vendor CVE Spike and Tag Spike Event Feed signals surfaced elevated, coordinated scanning/brute-force activity against Fortinet SSL VPN and Palo Alto Networks GlobalProtect portal infrastructure during the week of 2026-01-19. This activity follows the same pattern as a documented multi-vendor campaign (Cisco ASA, Palo Alto GlobalProtect, Fortinet SSL-VPN) observed Aug-Oct 2025, in which GreyNoise found 80% of such vendor-wide activity spikes were followed by a new CVE disclosure for that vendor within six weeks — including the Cisco ASA/FTD zero-days CVE-2025-20333 and CVE-2025-20362.
GreyNoise introduced two new Event Feed signal types — Vendor CVE Spike (monitors exploitation/scanning activity across a vendor's entire product portfolio rather than per-CVE) and Tag Spike (tracks sudden increases in IP counts matching a specific GreyNoise behavioral tag over rolling 2-hour windows, useful before a CVE exists) — explicitly to close the detection gap between the start of opportunistic internet-wide scanning and formal vulnerability disclosure. During the week of 2026-01-19, these feeds flagged a coordinated elevation in scanning and targeting activity against both Fortinet SSL VPN appliances and Palo Alto Networks GlobalProtect portals simultaneously, framed by GreyNoise as a probable early-warning signal for a forthcoming CVE affecting one or both vendors.
This pattern mirrors a well-documented precedent from Aug-Oct 2025: GreyNoise tracked a synchronized, cross-vendor reconnaissance campaign against Cisco ASA/FTD, Palo Alto GlobalProtect, and Fortinet SSL-VPN devices. It began with a 25,000+ IP scanning surge against Cisco ASA (2025-08-26, `/+CSCOE+/logon.html` probing), continued with brute-force waves against Fortinet SSL-VPN (780+ IPs on 2025-08-03, a second wave with a distinct TCP signature and FortiManager/FGFM targeting on 2025-08-05), and culminated in a ~500% surge (from a ~200 IP/day baseline to 1,300, then 2,200+ unique IPs) against Palo Alto GlobalProtect portals beginning 2025-10-03. GreyNoise assessed with high confidence that the three campaigns were at least partially driven by the same threat actor(s), citing shared TCP/client fingerprints, overlapping source subnets, and close temporal alignment. The Cisco ASA scanning wave preceded Cisco's 2025-09-25 disclosure of two zero-day vulnerabilities (CVE-2025-20333, CVSS 9.9; CVE-2025-20362, CVSS 6.5) in Secure Firewall ASA/FTD WebVPN, linked separately to the China-nexus ArcaneDoor espionage campaign and serious enough that CISA issued its third-ever Emergency Directive (ED 25-03).
GreyNoise's broader Fortinet-specific research found that spikes matching the 'Fortinet SSL VPN Bruteforcer' tag are significantly correlated with subsequently disclosed FortiOS/FortiGate vulnerabilities, consistent with Fortinet's history of pre-auth RCE flaws in SSL-VPN components (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) that were each exploited in the wild at or shortly after disclosure. No CVE, specific IP list, or ASN breakdown has yet been published for the 2026-01-19 Fortinet/Palo Alto spike itself; this record documents the signal and its historical analog so downstream detection/response teams can pre-stage monitoring ahead of an anticipated disclosure.
MITRE ATT&CK techniques used in TL-2026-1469
Discovery
T1046 Network Service Discovery
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
command-and-control
Credential Access
Lateral Movement
T1210 Exploitation of Remote Services
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure
Reconnaissance
T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning
Affected products and versions in Coordinated Scanning Campaign Against Fortinet SSL VPN and
- Fortinet — FortiOS SSL-VPN (sslvpnd)
Vulnerable versions: unspecified - pre-CVE scanning/brute-force target - Fortinet — FortiManager (FGFM protocol)
Vulnerable versions: unspecified - secondary target profile observed 2025-08-05 - Palo Alto Networks — PAN-OS GlobalProtect portal
Vulnerable versions: unspecified - pre-CVE scanning/login-brute-force target - Cisco — Secure Firewall ASA / FTD (WebVPN)
Vulnerable versions: ASA/FTD software prior to fix for CVE-2025-20333/CVE-2025-20362
Fixed in: patched releases per Cisco advisory for CVE-2025-20333 and CVE-2025-20362
Remediation for Coordinated Scanning Campaign Against Fortinet SSL VPN and
Patches
- Apply Cisco ASA/FTD patches for CVE-2025-20333 and CVE-2025-20362 immediately if not already applied
- Keep FortiOS, FortiGate, and FortiManager on current patched releases (history: CVE-2022-42475, CVE-2023-27997, CVE-2024-21762 pre-auth RCE)
- Monitor Fortinet PSIRT and Palo Alto Networks security advisories for a new disclosure in the coming weeks per the Vendor CVE Spike signal
Immediate actions
- Alert on and rate-limit/block traffic from source ASNs and IPs matching GreyNoise 'Fortinet SSL VPN Bruteforcer', 'Palo Alto Networks Login Scanner', and 'Cisco ASA Scanner' tags
- Enforce MFA on all Fortinet SSL-VPN and Palo Alto GlobalProtect portal logins to blunt credential brute-force/spraying
- Restrict management-plane exposure (FortiManager/FGFM, ASA WebVPN admin) to trusted networks only
- Subscribe to GreyNoise Vendor CVE Spike and Tag Spike webhook alerts for Fortinet and Palo Alto Networks to get early warning ahead of formal CVE disclosure
Workarounds
- Disable unused or legacy SSL-VPN/GlobalProtect web portals where remote access is not required
- Enforce unique, high-entropy credentials and lockout policies on VPN portals to reduce brute-force/credential-stuffing success
Longer-term hardening
- Given GreyNoise's 80%-within-six-weeks correlation between vendor-wide scanning spikes and new CVE disclosures, pre-stage patch-management and emergency-change processes for Fortinet FortiOS/FortiManager and Palo Alto PAN-OS now
- Deploy edge-device logging/EDR and centralize SSL-VPN/GlobalProtect authentication logs to a SIEM for anomaly detection
- Reduce internet-facing SSL-VPN/GlobalProtect attack surface via geofencing, allow-listing, or migration to broker/proxy-fronted remote access
Timeline of Coordinated Scanning Campaign Against Fortinet SSL VPN and
- GreyNoise observes an earlier, smaller Fortinet SSL-VPN scanning spike with a unique client TLS/TCP signature, later recognized as a precursor pattern.
- 780+ unique IPs trigger GreyNoise's 'Fortinet SSL VPN Bruteforcer' tag in a single day, well above the sub-baseline norm, targeting FortiOS SSL-VPN login.
- A second Fortinet-targeting wave begins with a distinct TCP signature; targeting shifts from FortiOS toward FortiManager/FGFM management protocol.
- 25,000+ unique IPs scan Cisco ASA devices in a single day (16,794 matching the 'Cisco ASA Scanner' tag); ~80% traced to a single Brazil-based botnet cluster probing /+CSCOE+/logon.html.
- Cisco ASA brute-force activity abruptly halts at approximately 6 PM EST.
- Brute-force activity resumes around 1 PM EST the same day Cisco discloses two zero-day vulnerabilities (CVE-2025-20333, CVSS 9.9; CVE-2025-20362, CVSS 6.5) in Secure Firewall ASA/FTD WebVPN, linked to the ArcaneDoor espionage campaign.
- CISA issues Emergency Directive ED 25-03 (its third-ever) in response to active exploitation of the Cisco ASA/FTD zero-days; GreyNoise publishes its Executive SITREP on the Cisco ASA scanning surge.
- Palo Alto GlobalProtect portal scanning jumps ~500% in 48 hours to ~1,300 unique IPs, against a 90-day baseline that rarely exceeded 200 IPs/day; 93% of source IPs classified suspicious, 7% malicious.
- Palo Alto GlobalProtect scanning activity peaks at 2,200+ unique IPs; GreyNoise assesses shared TCP fingerprints, overlapping subnets, and temporal alignment linking the Cisco, Fortinet, and Palo Alto waves to a common actor or coordinated cluster with high confidence.
- GreyNoise and multiple outlets (SecurityWeek, TheHackerNews, DarkReading) publicly report the coordinated multi-vendor Cisco/Fortinet/Palo Alto reconnaissance and brute-force campaign.
- Follow-on credential-based/password-spraying activity against Palo Alto GlobalProtect and Cisco VPN infrastructure is separately reported (CSO Online), consistent with continuation of the coordinated targeting.
- GreyNoise's newly launched Vendor CVE Spike and Tag Spike Event Feed signals detect a renewed, coordinated elevation in scanning/targeting activity against both Fortinet SSL VPN and Palo Alto GlobalProtect infrastructure during this week, ahead of any new CVE assignment for either vendor.
- GreyNoise publishes 'Introducing Vendor CVE and Tag Spike,' documenting the new detection capability and citing the Fortinet/Palo Alto activity as an example of the signal working as designed ahead of expected disclosure.
Sources cited for Coordinated Scanning Campaign Against Fortinet SSL VPN and
- Introducing Vendor CVE and Tag Spike
- Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign
- Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High
- Scanning Surge Targets Cisco ASA Devices
- Coordinated Brute Force Campaign Targets Fortinet SSL VPN
- Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day
- Surge in Scans on PAN GlobalProtect VPNs Hints at Attacks
- Attackers bring their own passwords to Cisco and Palo Alto VPNs
- GreyNoise Links Coordinated Firewall Scans to Potential Multi-Vendor Attack Campaign
- GreyNoise finds attacker activity surges before vulnerability disclosures
- Fortinet says SSL-VPN pre-auth RCE bug is exploited in attacks
- Building an Exploit for FortiGate Vulnerability CVE-2023-27997
Detection coverage for TL-2026-1469
As of 2026-01-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1469 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.