Web_Logo
Remote Support
Security Alert: New Fortinet Firewall Flaw Under Attack
Home » Security Alerts  »  Security Alert: New Fortinet Firewall Flaw Under Attack

Security Alert: New Fortinet Firewall Flaw Under Attack

A newly disclosed flaw in Fortinet's FortiOS firewall software is being actively exploited by attackers, and the US Cybersecurity and Infrastructure Security Agency has added it to its list of known exploited vulnerabilities.

  • What it is: The flaw lets an attacker pull sensitive information from an unpatched firewall without logging in, and can be used to get around a fix Fortinet issued for an earlier attack technique.
  • Who is affected: Any business running Fortinet FortiGate hardware or FortiOS software that has not applied the latest security update.
  • The risk: Attackers send specially crafted requests to exposed firewalls to bypass protections already put in place, potentially regaining a foothold in a network that was thought to be secured.
  • What to do: Confirm your FortiOS version is fully patched and check that no firewall management interface is exposed directly to the internet.

We recommend businesses running Fortinet hardware contact their IT provider promptly to confirm patch status, given this fix carries a firm remediation deadline of 10 August 2026.

Source: CISA Known Exploited Vulnerabilities Catalog