ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59718
Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy

CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days.

Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01.

9.868% KEV
  • Fortinet FortiOS 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3
  • Fortinet FortiProxy 7.0.0-7.0.21, 7.2.0-7.2.14, 7.4.0-7.4.10, 7.6.0-7.6.3
  • Fortinet FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6
  • +1 more
masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the…
CVE-2025-59719
Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO)

FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible.

Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent.

9.829%
  • fortinet fortiweb 8.0.0
  • fortinet fortiweb 7.6.0 through 7.6.4
  • fortinet fortiweb 7.4.0 through 7.4.9
largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud…
CVE-2026-24858
FortiCloud SSO Authentication Bypass Across Multiple Fortinet Products

CVE-2026-24858 is an authentication bypass (CWE-288) in FortiCloud single sign-on that lets an attacker who owns a FortiCloud account with any registered device log in to other customers' Fortinet devices that have FortiCloud SSO authentication enabled. It affects a wide range of 7.x/8.x builds of FortiOS, FortiProxy, FortiWeb, FortiAnalyzer, FortiManager, FortiNAC-F, and the Siemens RUGGEDCOM APE 1808. An attacker gains unauthorized access to devices registered to other accounts, and related reporting describes FortiGate devices being exploited to breach networks and steal service account credentials. Any organization running an affected build with FortiCloud SSO enabled is exposed. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-01-27 and Fortinet patched it after active FortiOS SSO exploitation was detected, and EPSS assigns an 86.1% probability of exploitation within 30 days.

Do: Upgrade all affected Fortinet products to the fixed releases specified in Fortinet's PSIRT advisory for CVE-2026-24858; as an interim mitigation, disable FortiCloud SSO authentication on affected devices and audit which devices are registered to your FortiCloud account. Review device logs for unexpected administrative logins or signs of service-account credential theft on FortiGate, and federal agencies must apply mitigations per BOD 22-01 (including CISA's cloud services guidance) or discontinue use of the product.

9.886% KEV
  • Fortinet FortiAnalyzer 7.6.0-7.6.5, 7.4.0-7.4.9, 7.2.0-7.2.11, 7.0.0-7.0.15
  • Fortinet FortiManager 7.6.0-7.6.5, 7.4.0-7.4.9, 7.2.0-7.2.11, 7.0.0-7.0.15
  • Fortinet FortiNAC-F 7.6.3-7.6.5
  • +4 more
masshundreds of thousands of devices potentially affected (Fortinet's FortiGate install base is in the millions and public internet scans have long shown hundreds…
Full article817 words · extracted from thehackernews.com · click to collapse

Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks.

The activity involves the exploitation of recently disclosed security vulnerabilities or weak credentials to extract configuration files containing service account credentials and network topology information, SentinelOne said in a report published today. The security outfit said the campaign has singled out environments tied to healthcare, government, and managed service providers.

"FortiGate network appliances have considerable access to the environments they were installed to protect," security researchers Alex Delamotte, Stephen Bromfield, Mary Braden Murphy, and Amey Patne said. "In many configurations, this includes service accounts which are connected to the authentication infrastructure, such as Active Directory (AD) and Lightweight Directory Access Protocol (LDAP)."

"This setup can enable the appliance to map roles to specific users by fetching attributes about the connection that’s being analyzed and correlating with the Directory information, which is useful in cases where role-based policies are set or for increasing response speed for network security alerts detected by the device."

However, the cybersecurity company noted that such access could be exploited by attackers who break into FortiGate devices through known vulnerabilities (e.g., CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858) or misconfigurations.

In one incident, the attackers are said to have breached a FortiGate appliance in November 2025 to create a new local administrator account named "support" and used it to set up four new firewall policies that allowed the account to traverse all zones without any restrictions.

The threat actor then kept periodically checking to ensure the device was accessible, an action consistent with an initial access broker (IAB) establishing a foothold and selling it to other criminal actors for monetary gain. The next phase of the activity was detected in February 2026 when an attacker likely extracted the configuration file containing encrypted service account LDAP credentials.

"Evidence demonstrates the attacker authenticated to the AD using clear text credentials from the fortidcagent service account, suggesting the attacker decrypted the configuration file and extracted the service account credentials," SentinelOne said.

The attacker then leveraged the service account to authenticate to the victim's environment and enroll rogue workstations in the AD, allowing them deeper access. Following this step, network scanning was initiated, at which point the breach was detected, and further lateral movement was halted.

In another case investigated in late January 2026, attackers swiftly moved from firewall access to deploying remote access tools like Pulseway and MeshAgent. In addition, the threat actor downloaded malware from a cloud storage bucket via PowerShell from Amazon Web Services (AWS) infrastructure.

The Java malware, launched via DLL side-loading, was used to exfiltrate the contents of the NTDS.dit file and SYSTEM registry hive to an external server ("172.67.196[.]232") over port 443.

"While the actor may have attempted to crack passwords from the data, no such credential usage was identified between the time of credential harvesting and incident containment," SentinelOne added.

Delamotte told The Hacker News that the company's Digital Forensics and Incident Response (DFIR) has observed similar techniques used in other cases, such as staging files in the USOShared paths. This likely suggests a wider campaign where FortiGate devices are not always used for initial access.

There is currently no evidence that the two aforementioned incidents are the work of the same threat actor, given the differences in the post-compromise techniques used.

"For example, the first incident we describe involved joining rogue attacker workstations to the AD," Delamotte added. "The other incident followed a multi-chain lateral movement operation that aligns with pre-ransomware activity. We were unable to conclude that it was the goal, as the attacks were blocked before any later-stage payloads were deployed."

The findings are yet another reminder that threat actors of varied motivations are actively targeting perimeter devices, turning them into prime initial access pathways for deeper compromises into enterprise networks. A common aspect that ties the two incidents together is the lack of adequate logging on the firewalls, preventing an understanding of how and when the attackers exactly gained initial access.

Organizations are recommended to ensure they have at least 14 days of log retention, as well as send all logs to a Security Incident and Event Monitoring (SIEM) to tackle scenarios where an attacker may delete them from a local machine in an attempt to cover up their tracks.

"NGFW appliances have become ubiquitous because they provide strong network monitoring capabilities for organizations by integrating security controls of a firewall with other management features, such as AD," it added. "However, these devices are high-value targets for actors with a variety of motivations and skill levels, from state-aligned actors conducting espionage to financially motivated attacks such as ransomware."

(The story was updated after publication to include additional insights from SentinelOne.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html