Cyber & Technology — 2026-03-27
FortiGate Firewall Exploits Enable Healthcare and Government Network Breaches Across 55 Countries
Threat actors are exploiting FortiGate Next-Generation Firewall vulnerabilities (CVE-2025-59718/59719 and CVE-2026-24858) to breach networks in healthcare, government, and managed service provider environments across 55 countries. Attackers extract configuration files containing service account LDAP/AD credentials using FortiOS's reversible encryption scheme, create rogue administrator accounts, and join unauthorized workstations to corporate domains. SentinelOne reported that over 600 FortiGate devices have been compromised, with some intrusions dating to November 2025, indicating a sustained campaign preceding public disclosure.
Analysis
The FortiGate campaign's targeting of healthcare and government networks across 55 countries, combined with FortiOS's reversible encryption for config files, represents a systemic architectural weakness rather than a one-off exploit. The November 2025 intrusion timeline preceding March 2026 disclosure suggests months of undetected access, a pattern consistent with APT-level operations rather than opportunistic attacks.
The FortiGate campaign's targeting of healthcare and government networks across 55 countries, combined with FortiOS's reversible encryption for config files, represents a systemic architectural weakness rather than a one-off exploit. The November 2025 intrusion timeline preceding March 2026 disclosure suggests months of undetected access, a pattern consistent with APT-level operations rather than opportunistic attacks.
3 sources
- FortiGate Edge Intrusions: Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise -
SentinelOne - Hackers Exploit FortiGate Firewalls in Widespread Attacks to Steal Network Credentials -
CyberPress - FortiGate firewall credentials being stolen after vulnerabilities discovered -
CSO Online