Listen to this Post

Introduction: A Growing Crisis in Enterprise Network Security
Fortinet devices sit at the core of thousands of enterprise and government networks worldwide, acting as gatekeepers for traffic, authentication, and policy enforcement. When flaws emerge in these systems, the consequences ripple far beyond a single vendor. A newly exploited authentication bypass tied to FortiCloud Single Sign-On (SSO) has once again placed Fortinet under intense scrutiny, after researchers revealed that tens of thousands of devices remain exposed online. The situation highlights a familiar but troubling pattern: critical vulnerabilities patched, yet widely unmitigated, while attackers move faster than defenders.
Discovery of Mass Exposure by Shadowserver
Internet security watchdog Shadowserver recently identified more than 25,000 Fortinet devices exposed to the internet with FortiCloud SSO enabled. These devices were discovered amid active attacks exploiting a critical authentication bypass vulnerability affecting several Fortinet products. According to Shadowserver’s telemetry, the exposed systems are not limited to one geography, reflecting the global footprint of Fortinet deployments.
The Vulnerabilities at the Center of the Attacks
The flaws are tracked as CVE-2025-59718, affecting FortiOS, FortiProxy, and FortiSwitchManager, and CVE-2025-59719, impacting FortiWeb. Both vulnerabilities enable attackers to bypass authentication mechanisms through the FortiCloud SSO login feature. Fortinet released patches on December 9, warning customers that exploitation could lead to unauthorized administrative access.
FortiCloud SSO and the FortiCare Connection
Fortinet clarified that the vulnerable FortiCloud SSO login feature is not enabled by default. Administrators must register their device with FortiCare, Fortinet’s support service, before SSO becomes active. Despite this safeguard, the scale of exposed devices suggests that many organizations either unintentionally enabled the feature or left it accessible without adequate network restrictions.
Active Exploitation Confirmed in the Wild
Cybersecurity firm Arctic Wolf confirmed that attackers are now actively exploiting the vulnerability. Threat actors are abusing the FortiCloud SSO mechanism by crafting malicious SAML authentication messages. These messages allow attackers to impersonate legitimate users and gain administrator-level access without valid credentials.
How the Attack Works in Practice
Once authentication is bypassed, attackers can access the Fortinet web management interface. From there, they can download system configuration files containing a wealth of sensitive data. This includes hashed administrator passwords, firewall rules, network topology details, and lists of exposed services. Even when passwords are hashed, attackers can attempt offline cracking or reuse credentials across environments.
Why Configuration Files Are a Goldmine
Configuration files represent a blueprint of an organization’s network defenses. Firewall policies reveal what traffic is allowed or blocked, exposed interfaces indicate potential entry points, and network layouts provide attackers with a roadmap for lateral movement. In the wrong hands, this data can significantly accelerate follow-on attacks.
Geographic Distribution of Exposed Devices
Shadowserver reports that over 5,400 of the exposed IP addresses are located in the United States, with nearly 2,000 in India. The remaining devices are spread across dozens of countries, reinforcing that the issue is not isolated to any single region or industry.
The Unknown State of Patch Adoption
Despite the availability of patches, there is currently no clear data on how many of the exposed devices have been secured against exploitation. This uncertainty complicates risk assessment efforts and leaves defenders guessing how much of the global attack surface remains vulnerable.
Independent Scans Confirm an Even Larger Problem
Macnica threat researcher Yutaka Sejiyama reported that his own scans identified over 30,000 Fortinet devices with FortiCloud SSO enabled and web management interfaces exposed to the internet. This discrepancy suggests that the true number of vulnerable systems may be higher than Shadowserver’s initial findings.
A Familiar Pattern of Exposed Admin Interfaces
Sejiyama expressed surprise at the scale of publicly accessible administrative interfaces. FortiOS admin GUIs have a long history of being targeted by attackers, making their continued exposure especially concerning. The persistence of this issue points to systemic misconfigurations rather than isolated mistakes.
CISA Steps In With an Emergency Mandate
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the FortiCloud SSO authentication bypass to its catalog of actively exploited vulnerabilities. Under Binding Operational Directive 22-01, U.S. government agencies were ordered to apply patches within one week, setting a deadline of December 23.
Why Government Action Matters
CISA’s inclusion of a vulnerability in its Known Exploited Vulnerabilities catalog signals that real-world attacks are underway and that the risk is immediate. While the directive applies directly to federal agencies, it often serves as a warning to private-sector organizations facing similar threats.
Fortinet’s Long History of Targeted Exploitation
Fortinet vulnerabilities are frequently leveraged by cyber-espionage groups, cybercriminals, and ransomware operators. Attackers value Fortinet devices because they sit at strategic network choke points, offering high-impact access when compromised.
Lessons From the Volt Typhoon Campaign
Earlier this year, Fortinet disclosed that the Chinese-linked Volt Typhoon group exploited two FortiOS SSL VPN vulnerabilities, CVE-2023-27997 and CVE-2022-42475. The attackers used these flaws to compromise a Dutch Ministry of Defence network, deploying custom Coathanger RAT malware to maintain persistent access.
A Pattern of Zero-Day Abuse
In November, Fortinet warned customers about a FortiWeb zero-day vulnerability, CVE-2025-58034, being exploited in the wild. This disclosure came just one week after Fortinet confirmed it had silently patched another FortiWeb zero-day, CVE-2025-64446, which was already being abused in widespread attacks.
The Cost of Delayed Visibility
Silent patches and delayed disclosures create blind spots for defenders. When organizations are unaware that a vulnerability exists, they cannot assess exposure or prioritize remediation. Attackers, meanwhile, often discover and weaponize these flaws quickly.
Identity and Access Management as a Weak Link
The FortiCloud SSO incident underscores broader issues with identity and access management. SSO systems are designed for convenience, but when misconfigured or exposed, they can become a single point of catastrophic failure.
Why IAM Failures Extend Beyond IT
Broken IAM practices do not only impact security teams. Compromised access controls can disrupt operations, expose sensitive business data, and erode trust with customers and partners. The ripple effects often reach legal, compliance, and executive leadership.
The Challenge of Securing Edge Devices
Edge devices like firewalls and proxies are often deployed quickly and forgotten once operational. Over time, management interfaces may remain exposed, credentials go unchanged, and optional features like SSO become attack vectors rather than productivity tools.
The Role of Continuous Asset Monitoring
Shadowserver’s findings highlight the importance of continuous external attack surface monitoring. Organizations frequently underestimate how many of their systems are visible from the internet, especially after years of incremental configuration changes.
What Undercode Say: Why This Fortinet Incident Matters
The FortiCloud SSO exposure is not just another vendor vulnerability; it reflects a structural weakness in how enterprises manage perimeter security devices. Fortinet continues to dominate the firewall and secure gateway market, making its flaws disproportionately attractive to attackers.
From Undercode’s perspective, the most alarming aspect is not the vulnerability itself, but the scale of exposure after patches were made available. This suggests that patch management alone is not enough. Organizations must also rethink default exposure models, especially for administrative interfaces.
SSO features, while valuable, should be treated as high-risk components when deployed on edge devices. Combining internet-facing management panels with federated authentication creates an enticing target, particularly when misconfigurations can nullify the protections SSO is meant to provide.
Undercode also notes a recurring pattern in Fortinet incidents: attackers consistently target the management plane rather than the data plane. Gaining control over configuration interfaces allows them to disable logging, weaken defenses, and establish persistence with minimal noise.
The repeated involvement of nation-state actors and advanced threat groups further elevates the risk profile. These adversaries are patient, well-resourced, and skilled at chaining vulnerabilities with misconfigurations to achieve long-term access.
Another concern is organizational complacency. Many administrators assume that edge devices are inherently hardened, leading to delayed updates and relaxed exposure controls. This mindset is increasingly dangerous as attackers specifically hunt for these assumptions.
Undercode believes that future Fortinet incidents will continue unless enterprises adopt stricter zero-trust principles for device management. Administrative access should be isolated, VPN-restricted, and monitored continuously, regardless of vendor assurances.
Finally, the incident reinforces the need for transparency from vendors. Timely disclosure, clear mitigation guidance, and proactive customer communication are essential to reduce the window of exploitation. Without these, even well-resourced organizations remain vulnerable.
Fact Checker Results
Validation of Exposure Claims ✅
Independent scans from Shadowserver and Macnica confirm that tens of thousands of Fortinet devices expose FortiCloud SSO-enabled interfaces.
Confirmation of Active Exploitation ✅
Arctic Wolf and CISA have both verified that the vulnerabilities are actively exploited in real-world attacks.
Patch Availability Status ✅
Fortinet released patches on December 9, but the level of global adoption remains unclear.
Prediction
Increased Targeting of Edge SSO Features 🔮
Attackers are likely to expand their focus on SSO mechanisms embedded in network appliances, not just traditional identity providers.
Regulatory Pressure Will Intensify 🔮
Government agencies may impose stricter timelines and penalties for unpatched perimeter devices following repeated incidents.
Fortinet Hardening Guidance Will Evolve 🔮
Future Fortinet recommendations are expected to further restrict default exposure of management interfaces and SSO features.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




