Tag: Automated FortiGate Attacks

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
News

Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations

A "new cluster of automated malicious activity" involving illegal firewall configuration changes on Fortinet FortiGate devices has been reported by cybersecurity firm Arctic Wolf. It stated that the activity started on January 15, 2026, and that it is comparable to a December 2025 campaign that used CVE-2025-59718 and CVE-2025-59719 to record malicious SSO logins on FortiGate appliances against the admin account from several hosting providers. When the FortiCloud single sign-on (SSO) capability is enabled on impacted devices, both vulnerabilities enable unauthenticated bypass of SSO login authentication via manipulated SAML messages. The flaws affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. According to Arctic Wolf, this activity included exfiltrating firewall confi...