FortiGate Firewalls Compromised: Why Patching Didn’t Fix the Problem

FortiGate Firewalls Compromised: Why Patching Didn’t Fix the Problem

June 19, 2026 · 7 min · Season 2 · Episode 41

About this episode

This episode discusses the compromises of FortiGate firewalls and the inadequacy of patching in preventing persistent access by attackers.

Thousands of Fortinet FortiGate devices have been compromised—even in organizations that already applied security patches. In this episode of IT SPARC Cast – CVE of the Week, John and Lou explain how attackers maintained persistence after earlier breaches, why patching alone wasn’t enough, and what every organization running FortiGate firewalls must do immediately to verify they haven’t already been compromised. ⸻ 📄 Show Notes 🚨 CVE of the Week (Special Security Alert): FortiGate Compromises This week we’re covering a major Fortinet security incident affecting organizations around the world. Unlike most episodes, this isn’t focused on a single CVE. Instead, attackers are leveraging previously exploited FortiGate vulnerabilities and maintaining persistent access even after organizations patched the original flaws. The key lesson: 👉 Patching does not remove an attacker who is already inside. ⸻ ⚠️ What Happened? Large organizations across multiple industries have reported compromises involving FortiGate firewalls and VPN infrastructure. Attackers reportedly: Exploited previously disclosed Fortinet vulnerabilities Established persistence mechanisms Maintained access after patches…

People in this episode

Host: John Barger

Guest: Lou

Topics covered

Keywords

Mentioned in this episode

Organizations: Fortinet

Products: FortiGate

More episodes of IT SPARC Cast

Explore listener stats, chart rankings, contacts and more on the IT SPARC Cast podcast page.