‹ Back to Home

Attackers Are Abusing FortiGate Firewalls as Entry Points: What You Need to Know

Threat actors are exploiting critical vulnerabilities in Fortinet's FortiGate firewalls to gain initial access into enterprise networks — turning the very devices meant to protect organizations into open doors for attackers.

Keerthika 7 min read 536
Follow on Google
Updated 2 weeks ago
Security Attackers Are Abusing FortiGate Firewalls as Entry Points: What You Need to Know 7 min left Follow on Google
Attackers Are Abusing FortiGate Firewalls as Entry Points: What You Need to Know

TamilTech AI summary

Attackers are mass-exploiting critical FortiGate FortiOS flaws—especially unauthenticated SSL-VPN bugs like CVE-2024-21762, CVE-2023-27997, and CVE-2024-23113—so a crafted request can give them root-level code execution on the firewall itself and turn your perimeter guard into the front door. That matters because groups from Volt Typhoon to ransomware crews and initial-access brokers are using it against banks, hospitals, government, manufacturing, and critical infrastructure worldwide, including Indian orgs that CERT-In has already warned about. Once inside, they harvest VPN credentials, move laterally as “legit” users, and sometimes plant firmware backdoors that even survive patches and factory resets, so simply updating is not enough if you never hunted for compromise. Hundreds of thousands of FortiGate SSL-VPN portals have been exposed online, and old leaked credentials often still work when passwords were never rotated. If you run FortiGate, patch to the fixed FortiOS builds now, assume breach and check logs, odd admin accounts, and strange files, rotate all VPN credentials, lock management to trusted IPs, prefer IPsec over SSL-VPN when you can, and turn on MFA—because a firewall is software that needs the same urgent care as any other internet-facing system.

  • Which FortiGate vulnerability is being actively exploited?
  • Who is behind these FortiGate attacks?
  • How do I know if my FortiGate device is compromised?
  • What should I do immediately if I use FortiGate?

AI-assisted summary, checked by the TamilTech editorial team.

Attackers Are Abusing FortiGate Firewalls as Entry Points: What You Need to Know

Firewalls are supposed to be the guardians of your network — the digital bouncers that keep the bad guys out. But what happens when the bouncer itself becomes the door? That's exactly what's happening with Fortinet's FortiGate firewalls, which threat actors are now actively exploiting as entry points into enterprise networks around the world.

CISA (the US Cybersecurity and Infrastructure Security Agency), Fortinet's own PSIRT team, and multiple threat intelligence firms have raised alarms: FortiGate vulnerabilities are being mass-exploited in the wild, with attackers targeting banks, hospitals, critical infrastructure, government agencies, and large corporations across the globe — including in India.

The Vulnerabilities at the Core

FortiGate devices run FortiOS, Fortinet's operating system for its firewall and VPN appliances. Over the past 18 months, several critical vulnerabilities have been discovered — and actively abused — in FortiOS, particularly in its SSL-VPN component:

Premium Content

You've read all your free articles today. Subscribe to continue reading.

You've used 3 of 3 free articles today.

Subscribe Now

Already subscribed? Sign in

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications