Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59718 | Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days. Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01. | 9.8 | 68% | KEV |
| masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the… | |
| CVE-2025-59719 | Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO) FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible. Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent. | 9.8 | 29% |
| largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud… |
Full article319 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 23, 2026Network Security / Vulnerability
Fortinet has officially confirmed that it's working to completely plug a FortiCloud SSO authentication bypass vulnerability following reports of fresh exploitation activity on fully-patched firewalls.
"In the last 24 hours, we have identified a number of cases where the exploit was to a device that had been fully upgraded to the latest release at the time of the attack, which suggested a new attack path," Fortinet Chief Information Security Officer (CISO) Carl Windsor said in a Thursday post.
The activity essentially mounts to a bypass for patches put in place by the network security vendor to address CVE-2025-59718 and CVE-2025-59719, which could allow unauthenticated bypass of SSO login authentication via crafted SAML messages if the FortiCloud SSO feature is enabled on affected devices. The issues were originally addressed by Fortinet last month.
However, earlier this week, reports emerged of renewed activity in which malicious SSO logins on FortiGate appliances were recorded against the admin account on devices that had been patched against the twin vulnerabilities. The activity is similar to incidents observed in December, shortly after the disclosure of the CVE-2025-59718 and CVE-2025-59719.
The activity involves the creation of generic accounts for persistence, making configuration changes granting VPN access to those accounts, and the exfiltration of firewall configurations to different IP addresses. The threat actor has been observed logging in with accounts named "[email protected]" and "[email protected]."
As mitigations, the company is urging the following actions -
- Restrict administrative access of edge network device via the internet by applying a local-in policy
- Disable FortiCloud SSO logins by disabling "admin-forticloud-sso-login"
"It is important to note that while, at this time, only exploitation of FortiCloud SSO has been observed, this issue is applicable to all SAML SSO implementations," Fortinet said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/01/fortinet-confirms-active-forticloud-sso.html