Attackers Target Fortinet Firewalls Again. And This Time, Automated
Cybersecurity company Arctic Wolf warned of a new wave of automated attacks targeting Fortinet FortiGate firewalls. Activity has been observed since mid-January 2026 and includes unauthorized changes to device configurations, creation of accounts for persistence, and exfiltration of firewall configurations.

Cybersecurity company Arctic Wolf warned of a new wave of automated attacks targeting Fortinet FortiGate firewalls. Activity has been observed since mid-January 2026 and includes unauthorized changes to device configurations, creation of accounts for persistence, and exfiltration of firewall configurations.
Attackers are exploiting weaknesses in FortiCloud Single Sign-On (SSO) and can reach the administrative interface without knowing credentials. Worryingly, the entire attack takes place extremely quickly — within seconds — which greatly reduces the chance of timely detection.
What we know about the attack technique
According to available information, vulnerabilities CVE-2025-59718 and CVE-2025-59719 are being exploited, which allow bypassing SSO authentication using modified SAML messages when FortiCloud SSO is enabled on the device. This affects not only FortiGate but the wider Fortinet product ecosystem.
After successful access, attackers create new administrative accounts with inconspicuous names, give them VPN access, and then export the complete firewall configuration. That configuration gives attackers a detailed view of the organization's network architecture and prepares the ground for further phases of the attack.
Why this is relevant for Czech organizations too
The Národní úřad pro kybernetickou a informační bezpečnost also warned about this wave of attacks. That confirms this is not a marginal incident but a real ongoing threat that can affect organizations in the Czech Republic.
Recommendations at this time mainly include limiting or disabling FortiCloud SSO logins and thoroughly checking changes to firewall configurations.
What this implies
The case shows that modern perimeter attacks are increasingly automated, fast, and stealthy. Instead of immediate destruction, attackers focus on quietly taking control and collecting information that can be abused later.
Firewalls, traditionally seen as the last line of defense, are thus becoming primary targets again.
What common recommendations don't say — and where administrators most often fail?
What specific traces does this attack leave in FortiGate logs? How can you tell that a configuration export has already occurred even when the firewall is still „operational“? And why can a device be compromised even if it is fully updated?
All this in the CCTV+ subscriber section