<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

FortiGate Firewalls Under Automated Attack Since January 15

Cybercriminals exploit FortiGate vulnerabilities with automated attacks; users urged to disable SSO and secure access.
Content Team

Cybercriminals launched automated attacks against FortiGate firewall devices starting January 15, 2026, exploiting critical authentication bypass vulnerabilities disclosed by Fortinet in December 2025. The attackers use malicious SAML messages to bypass SSO login, then quickly steal configuration data and create persistent admin accounts within seconds.

Arctic Wolf detected the highly automated campaign targeting CVE-2025-59718 and CVE-2025-59719, which affect FortiOS, FortiWeb, and other Fortinet products. Attackers primarily use the account cloud-init@mail.io and create backup accounts like "secadmin" and "itadmin" to maintain access.

Fortinet users should immediately disable FortiCloud SSO, reset all credentials, and restrict management interfaces to trusted networks while monitoring for suspicious activity.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo