Fortinet customers face heightened security risks after breach of FortiGate devices

Fortinet customers face heightened security risks after breach of FortiGate devices

Automated attacks on Fortinet FortiGate devices exploit an SSO flaw, allowing creation of rogue accounts and data theft. A patch may not fully protect users.

NeboAI I summarize the news with data, figures and context
IN 30 SECONDS

IN 1 SENTENCE

SENTIMENT
Neutral

𒀭
NeboAI is working, please wait...
Preparing detailed analysis
Quick summary completed
Extracting data, figures and quotes...
Identifying key players and context
DETAILED ANALYSIS
SHARE

NeboAI produces automated editions of journalistic texts in the form of summaries and analyses. Its experimental results are based on artificial intelligence. As an AI edition, texts may occasionally contain errors, omissions, incorrect data relationships and other unforeseen inaccuracies. We recommend verifying the content.

Automated attacks targeting Fortinet FortiGate devices have been reported, leading to the unauthorized creation of accounts and theft of firewall configuration data. This campaign began on January 15, 2026, as per a report from cybersecurity firm Arctic Wolf.

The attackers are exploiting an unpatched vulnerability in the devices' single sign-on (SSO) feature, which has previously been linked to a critical flaw identified as CVE-2025-59718. This specific vulnerability allows for an authentication bypass via malicious SAML messages, posing significant risks to users.

Fortinet is aware of the situation, with reports indicating that the latest version of FortiOS (7.4.10) does not completely resolve the authentication issues from earlier patches. Upcoming releases, including FortiOS 7.4.11 and 7.6.6, are anticipated to address these concerns fully. Users are advised to disable FortiCloud SSO temporarily to mitigate the risk of further attacks until a comprehensive solution is implemented.

Want to read the full article? Access the original article with all the details.
Read Original Article
TL;DR

This article is an original summary for informational purposes. Image credits and full coverage at the original source. · View Content Policy

Editorial
Editorial Staff

Our editorial team works around the clock to bring you the latest tech news, trends, and insights from the industry. We cover everything from artificial intelligence breakthroughs to startup funding rounds, gadget launches, and cybersecurity threats. Our mission is to keep you informed with accurate, timely, and relevant technology coverage.

Press Enter to search or ESC to close