A “new cluster of automated malicious activity” involving illegal firewall configuration changes on Fortinet FortiGate devices has been reported by cybersecurity firm Arctic Wolf.
It stated that the activity started on January 15, 2026, and that it is comparable to a December 2025 campaign that used CVE-2025-59718 and CVE-2025-59719 to record malicious SSO logins on FortiGate appliances against the admin account from several hosting providers.
When the FortiCloud single sign-on (SSO) capability is enabled on impacted devices, both vulnerabilities enable unauthenticated bypass of SSO login authentication via manipulated SAML messages. The flaws affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager.
According to Arctic Wolf, this activity included exfiltrating firewall configurations, creating generic accounts meant for persistence, and making configuration adjustments read more about Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
