FortiGate Vulnerability Weaponized for Network Access and Data Theft
Mar 10, 2026 // 21:50 - Norina Velotta


Threat actors are actively compromising Fortinet FortiGate devices to breach internal networks and steal sensitive service account credentials. These campaigns often target configuration files that contain encrypted or clear-text credentials for services like Active Directory (AD) and LDAP.

Key Exploitation Methods

Adversaries use a combination of known vulnerabilities and weak security hygiene to gain initial access:

  • Vulnerability Exploitation: Attackers leverage critical flaws such as CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858 to bypass authentication.
  • Weak Credentials: Many breaches occur due to exposed management ports and weak, single-factor credentials, which allow for automated brute-force attacks.
  • AI-Augmented Attacks: Recent reports fromĀ AWS highlight actors using generative AI to automate mass scanning and configuration extraction at scale.

Post-Exploitation Activities

Once a device is compromised, attackers typically perform the following:

  • Configuration Extraction: Stealing the device’s configuration file to harvest service account credentials and map network topology.
  • Credential Harvesting: Decrypting configuration files to obtain clear-text credentials for accounts like fortidcagent, which are then used to authenticate to the internal AD.
  • Lateral Movement: Using stolen VPN or admin credentials to connect to internal networks, deploy remote management tools (e.g., Pulseway, MeshAgent), and access backup infrastructure.
  • Persistence: Creating rogue local administrator accounts (e.g., “support”) and unrestricted firewall policies to maintain long-term access.

Recommended Mitigations

To defend against these intrusions, organizations should follow guidance from FortiGuard Labs and CISA:

  • Immediate Patching: Update FortiOS and related firmware to the latest versions to address active SSO and authentication bypass flaws.
  • Enforce MFA: Implement Multi-Factor Authentication for all administrative and VPN access.
  • Restrict Access: Use local-in policies to limit administrative interface access to trusted IP addresses only.
  • Credential Rotation: Reset and rotate all service account passwords, VPN credentials, and SSH keys if a compromise is suspected.

#access  #and  #data  #for  #fortigate  #network  #news  #theft  #vulnerability  #weaponized   —   News