Imagine your front door has a lock that anyone with the right knowledge can open without a key - and burglars already know it. Something similar is happening at Fortinet right now. A critical security flaw has been found in FortiGate firewalls, and it is already being actively exploited in attacks. For many companies in wholesale, manufacturing and transport, this firewall is exactly that: the front door of the company network. And that door is now standing ajar.
Why firewalls are such an attractive target
A firewall is the device that decides what is and isn’t allowed into your company network. Everything - your email, your business software, the connection with suppliers, access for remote workers - passes through it. That’s exactly why it’s such a coveted target. Anyone who manages to break into a firewall no longer needs to find all sorts of small workarounds to get in: they’re standing right at the front door, with a view of everything happening behind it.
Firewalls are also often in use for years without anyone actively paying attention to them anymore. They “just work” - until a flaw like this shows that even this kind of quiet, reliable device can be vulnerable. And because brands like Fortinet are used by hundreds of thousands of companies worldwide, the payoff for attackers is huge: one vulnerability, countless potential targets.
What this means for your business processes
If an attacker gains access to your firewall, they potentially get a view of - and sometimes control over - the entire network behind it. Think of:
- Your ERP or planning system, used to manage orders, stock and delivery times.
- The link to transport planning or warehouse systems, which often need to run 24/7.
- Access to financial systems and customer data.
- The connection between locations or with a production site.
When exploited, it’s not always immediately about stealing data. Often the initial goal is simply to maintain access and explore. Only later - sometimes weeks later - does the real incident follow: ransomware that shuts down your systems, or a quiet data theft you only discover once it’s already too late. For businesses that run on tight schedules - a truck that has to leave on time, a production line that can’t afford to stop - network downtime isn’t an inconvenience, it’s a direct loss of revenue and customer trust.
What you need to have done now
You don’t have to solve this yourself, but you do need to be sure it’s being handled. Discuss this with your IT partner and ask for the following steps:
1. Confirm whether you use Fortinet equipment. Sounds obvious, but for companies with multiple locations or a history of acquisitions, this isn’t always immediately clear. Have this checked explicitly.
2. Patch immediately. Fortinet has released an update that closes the flaw. This update needs to be installed as soon as possible - not next month during routine maintenance, but this week.
3. Check for signs of exploitation. Because the flaw is already being actively used, patching alone isn’t enough if an attacker has already gotten through. Ask your IT partner to check for indicators of compromise: unusual login attempts, unknown admin accounts, or abnormal traffic from the firewall.
4. Restrict access to the management panel. Where possible, the firewall’s management panel should not be reachable from the internet. This is a good moment to verify that together with your IT partner.
If you don’t know what firewall you have
Many business owners know there’s “a firewall” somewhere, but not which brand or version. That’s nothing to be embarrassed about - it’s exactly the kind of detail your IT partner should be keeping track of. If it’s not clear right now, this is a good time to simply ask. A short phone call or email is enough to get clarity.
A few questions we’re often asked
How do I know if my business has already been affected?
Without investigation, that’s hard to say with certainty. Unusual behaviour such as slow systems, unexplained login alerts or new user accounts can be a signal, but their absence is no guarantee either. Only targeted review of log files by your IT partner gives real clarity.
Should we stop using Fortinet equipment altogether?
No, that’s not necessary. Fortinet is an established and widely used brand, and this kind of vulnerability occurs occasionally at virtually every manufacturer. What matters more than the brand is how quickly updates are applied and how well the device is maintained.
We normally patch periodically - isn’t that enough?
For most updates, periodic patching is fine. But with a critical flaw that’s already being actively exploited, every day counts: the longer you wait, the greater the chance an attacker gets there first. This is one of the rare moments where “we’ll do it at the next maintenance round” can be too late.
What can we do to respond faster to this kind of risk in the future?
Agree with your IT partner on how critical alerts from manufacturers like Fortinet are monitored and how quickly action is taken. A standing agreement on this - including who is responsible for what - prevents a flaw like this from falling through the cracks.
Want to have it checked whether your firewall is secure and the latest updates have been applied? We’re happy to help.