INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FortiCloud SSO Bypass Exploited on Fully Patched Fortigates

| 2026-01-23 12:30 CRITICAL HIGH
Executive Summary AI-generated
The threat actor has been observed logging in with accounts named "[email protected]" and "[email protected]", exploiting a vulnerability in FortiCloud SSO authentication bypass, which allows for unauthenticated access to SAML login authentication via crafted messages. This is not the first incident of renewed activity following the disclosure of CVE-2025-59718 and CVE-2025-59719, suggesting that the threat actor has been adapting its tactics. The exploit appears to be targeting fully-patched FortiGate firewalls, which have been patched in December but are still vulnerable due to outdated configurations.
Technical Mitigations AI-generated
* Implement a robust patch management policy: Ensure that all FortiGate firewalls and other affected devices receive timely patches for CVE-2025-59718 and CVE-2025-59719. This includes applying the latest release of FortiOS, as well as any subsequent security updates. * Use secure authentication protocols: Implement strong authentication protocols such as multi-factor authentication (MFA) or token-based authentication to prevent unauthorized access to SSO-enabled features on affected devices. * Monitor and log suspicious activity: Continuously monitor logs for signs of suspicious activity, including login attempts from unknown IP addresses or accounts with elevated privileges. This can help identify potential security breaches before they escalate into full-scale attacks. * Implement a secure configuration management process: Ensure that all firewall configurations are properly documented, reviewed, and approved by authorized personnel. Use secure configuration management tools to track changes and ensure that only trusted configurations are deployed. * Use a web application firewall (WAF) with built-in security features: Consider implementing a WAF on FortiGate firewalls to detect and prevent common web attacks such as SQL injection or cross-site scripting (XSS). This can help protect against the types of SSO intrusions that have been reported.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-59719CVE-2025-59719 CVE-2025-59718CVE-2025-59718
Target & Sectors
Global Scope
Incident Timeline
2025-12-24
Fortinet confirmed active FortiCloud Single Sign-On (SSO) bypass vulnerabilities in fully patched FortiGate firewalls on December 24, 2025.
organisation Fortinet
December 2025
Threat actors used CVE-2025-59718 and CVE-2025-59719 to bypass SSO on fully patched FortiGate firewalls.
infrastructure Fortigate
organisation CVE-2025-59718
organisation CVE-2025-59719
organisation SSO
organisation FortiGate
January 15, 2026
Threat actors used a previously unknown vulnerability in FortiGate firewalls to bypass Single Sign-On (SSO) authentication on fully patched appliances.
infrastructure Fortigate
organisation CVE-2025-59718
organisation CVE-2025-59719
organisation SSO
organisation FortiGate
January 15
Threat actors used compromised SSO accounts to target Fortinet's FortiGate appliances on January 15.
infrastructure Fortigate
organisation SSO
organisation Fortinet
Jan 22, 2026
Threat actors exploited a previously unknown vulnerability in FortiGate firewalls to bypass Secure SSO authentication on fully patched Fortinet FortiCloud gateways.
Jan 22
Threat actors used automated tools to bypass the SSO protection on FortiGate firewalls.
infrastructure Fortigate
organisation Fortinet FortiGate
Jan 23, 2026
Threat actors exploited a vulnerability in FortiCloud SSO to bypass fully patched Fortigate firewalls.
organisation IP
infrastructure Fortigate
organisation FortiGate
organisation CVE-2025-59718
organisation CVE-2025
organisation SSO
organisation CVE-2025-59719
organisation Disable FortiCloud SSO
organisation FortiCloud SSO
Jan 23
Fortinet confirmed it is working to patch a FortiCloud SSO authentication bypass vulnerability in fully-patched firewalls.
organisation Network Security / Vulnerability
2026-01-23
Fortinet has acknowledged that its FortiCloud single sign-on (SSO) feature is vulnerable to a bypass, allowing attackers to log in from compromised IP addresses and alter firewall configurations.
organisation IP
organisation GUI
organisation [email protected]
infrastructure Fortigate
organisation FortiGate
organisation CVE-2025-59719
organisation CVE-2025-59718
organisation CVE-2025
infrastructure 7.4.11
infrastructure 7.6.6
infrastructure 8.0.0
infrastructure 7.4.10
organisation Reddit
infrastructure 7.4.9
organisation FortiOS 7.4.10
organisation FortiOS 7.4.9
organisation FortiCloud
organisation FortiWeb
organisation FortiProxy
organisation The Hacker News
Tactical Metrics
Metrics
infrastructure
​Fortigate
Affected Product
Metrics
infrastructure
​7.4.10
Software Version
Metrics
infrastructure
​7.4.9
Software Version
Metrics
infrastructure
​7.4.11
Software Version
Metrics
infrastructure
​7.6.6
Software Version
Metrics
infrastructure
​8.0.0
Software Version
Intelligence Sources