Gen. partnerAlgotech

Attackers Target Fortinet Firewalls Again. And This Time, Automated

Cybersecurity company Arctic Wolf warned of a new wave of automated attacks targeting Fortinet FortiGate firewalls. Activity has been observed since mid-January 2026 and includes unauthorized changes to device configurations, creation of accounts for persistence, and exfiltration of firewall configurations.

|
January 27, 2026
Attackers Target Fortinet Firewalls Again. And This Time, Automated

Cybersecurity company Arctic Wolf warned of a new wave of automated attacks targeting Fortinet FortiGate firewalls. Activity has been observed since mid-January 2026 and includes unauthorized changes to device configurations, creation of accounts for persistence, and exfiltration of firewall configurations.

Attackers are exploiting weaknesses in FortiCloud Single Sign-On (SSO) and can reach the administrative interface without knowing credentials. Worryingly, the entire attack takes place extremely quickly — within seconds — which greatly reduces the chance of timely detection.

What we know about the attack technique

According to available information, vulnerabilities CVE-2025-59718 and CVE-2025-59719 are being exploited, which allow bypassing SSO authentication using modified SAML messages when FortiCloud SSO is enabled on the device. This affects not only FortiGate but the wider Fortinet product ecosystem.

After successful access, attackers create new administrative accounts with inconspicuous names, give them VPN access, and then export the complete firewall configuration. That configuration gives attackers a detailed view of the organization's network architecture and prepares the ground for further phases of the attack.

Why this is relevant for Czech organizations too

The Národní úřad pro kybernetickou a informační bezpečnost also warned about this wave of attacks. That confirms this is not a marginal incident but a real ongoing threat that can affect organizations in the Czech Republic.

Recommendations at this time mainly include limiting or disabling FortiCloud SSO logins and thoroughly checking changes to firewall configurations.

What this implies

The case shows that modern perimeter attacks are increasingly automated, fast, and stealthy. Instead of immediate destruction, attackers focus on quietly taking control and collecting information that can be abused later.

Firewalls, traditionally seen as the last line of defense, are thus becoming primary targets again.

What common recommendations don't say — and where administrators most often fail?

What specific traces does this attack leave in FortiGate logs? How can you tell that a configuration export has already occurred even when the firewall is still „operational“? And why can a device be compromised even if it is fully updated?

All this in the CCTV+ subscriber section

Treat yourself. Try CZECH CYBER TV for just 125 CZK per month

Already a subscriber?

Sign in
  • •CZECH CYBER TV subscription from 125 CZK per month with annual payment.
  • •You save 75 CZK per month.
  • •You can cancel the automatic renewal at any time.
Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.