Listen to this Post

Fortinet has issued a serious warning after confirming that critical vulnerabilities in its FortiCloud single sign-on (SSO) system are being actively exploited by threat actors. These flaws allow attackers to bypass authentication and gain administrative access to enterprise devices, posing a major risk to organizations that rely on Fortinet infrastructure for network security. With real-world attacks already underway, Fortinet urges companies to take immediate action to safeguard their systems.
FortiCloud SSO Vulnerabilities: A Detailed Overview
In December 2025, Fortinet discovered two severe FortiCloud SSO bypass vulnerabilities, tracked as CVE-2025-59718 and CVE-2025-59719, during an internal code review. These flaws affect multiple enterprise products, including FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager, allowing unauthenticated attackers to bypass SSO authentication using crafted SAML requests.
CVE ID CVSS Score Affected Products Attack Vector Status
CVE-2025-59718 9.8 (Critical) FortiOS, FortiWeb, FortiProxy, FortiSwitch Manager Network/SAML Bypass Active Exploitation
CVE-2025-59719 9.8 (Critical) FortiOS, FortiWeb, FortiProxy, FortiSwitch Manager Network/SAML Bypass Active Exploitation
Fortinet reports that attackers are actively exploiting these vulnerabilities, including successful breaches against fully patched systems, suggesting a previously unknown attack vector. Threat actors typically establish persistent local admin accounts immediately after gaining access, ensuring ongoing control even if SSO credentials are disabled.
Indicators of Compromise (IOCs)
Organizations should monitor for the following IOCs:
Compromised User Accounts:
[email protected]
[email protected]
Source IP Addresses:
104.28.244.115
104.28.212.114
37.1.209.19 (third-party observed)
217.119.139.50 (third-party observed)
Malicious Admin Accounts Created:
audit
backup
itadmin
secadmin
support
Fortinet emphasizes auditing all administrator accounts for unexpected entries created during suspicious timeframes.
Recommended Immediate Actions
Fortinet recommends organizations take the following steps:
Restrict Administrative Access: Limit administrative interfaces to trusted IP ranges to prevent exposure of management ports.
Disable FortiCloud SSO Temporarily: Use the CLI command set admin-forticloud-sso-login disable to prevent unauthorized access.
Monitor and Update: Regularly check Fortinet’s PSIRT page and subscribe to update notifications.
If IOCs are found, treat the system as fully compromised and follow these remediation steps:
Update firmware to the latest version (7.6 recommended)
Restore configuration from a known-clean backup
Rotate all administrative and LDAP/AD credentials
Conduct a thorough audit of VPN configurations and user accounts
Fortinet is actively developing a permanent patch to close the new attack vector and will release an updated advisory with the patch timeline.
What Undercode Say:
The FortiCloud SSO bypass vulnerabilities highlight a growing trend of SSO-targeted attacks, where threat actors exploit centralized authentication systems to gain broad network access. Enterprises increasingly rely on SSO for convenience, but these systems can become single points of failure if compromised.
The active exploitation of these flaws demonstrates that attackers are not waiting for patch releases—they are probing defenses in real-time, targeting organizations with internet-facing management interfaces. The rapid creation of persistent admin accounts suggests sophisticated operational planning: attackers intend long-term access, not just quick breaches.
From a defensive perspective, organizations must adopt a layered security approach. Restricting access by IP range and temporarily disabling vulnerable SSO features are immediate mitigations, but they cannot replace comprehensive auditing and credential rotation. Fortinet’s reliance on firmware patches also underscores the importance of continuous monitoring and vulnerability management, as attackers often find new bypass vectors faster than vendors can patch them.
Furthermore, the involvement of multiple Fortinet products in these vulnerabilities highlights supply chain risk: a single authentication flaw can ripple across an organization’s infrastructure, affecting firewalls, proxies, and network switches simultaneously. Enterprises should evaluate network segmentation, ensuring that compromise in one system does not propagate broadly.
Finally, organizations must treat even fully patched systems with caution. The reported exploitation of updated Fortinet devices signals that attackers are developing creative bypasses that ignore existing fixes. This trend emphasizes the need for proactive threat hunting, rather than reactive patch application.
Fact Checker Results
✅ Vulnerability Confirmation: CVE-2025-59718 and CVE-2025-59719 confirmed by Fortinet.
✅ Active Exploitation: Multiple reports indicate attacks are in progress, including on patched systems.
❌ Full Patch Protection: Current patches do not completely mitigate the new attack vector.
Prediction
🚨 The FortiCloud SSO vulnerabilities will likely lead to a surge in targeted attacks on enterprises using Fortinet products.
🔒 Organizations that delay mitigation measures risk long-term compromise due to persistent administrative accounts.
⚡ Expect accelerated patch releases from Fortinet and third-party threat intelligence updates highlighting new bypass methods in 2026.
If you want, I can also create a visual infographic showing attack flow and remediation steps for this FortiCloud SSO exploit—it would make the article even more actionable for IT teams. Do you want me to do that next?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




