25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks
Over 25,000 Fortinet devices globally have been identified with FortiCloud Single Sign-On (SSO) enabled, creating potential exposure to remote attacks.
Over 25,000 Fortinet devices globally have been identified with FortiCloud Single Sign-On (SSO) enabled, creating potential exposure to remote attacks.
This information was derived from enhanced device fingerprinting in a new Device Identification report, which revealed these systems were openly advertising their SSO configuration through global IP address scans.
FortiCloud SSO facilitates streamlined authentication across Fortinet's product ecosystem, including firewalls, switches, and access points such as the FortiGate series. However, publicly exposing this feature may alert attackers to test for vulnerabilities.
The Shadowserver Foundation identified at least 25,000 unique IPs within regions such as North America, Europe, and Asia-Pacific. This exposure highlights the risk of management interfaces being accessed without authorization.
Recent vulnerabilities in Fortinet products have been noted, specifically CVE-2025-59718 and CVE-2025-59719, which have been rated with high severity scores by CVSS. These vulnerabilities affect systems integrated with FortiCloud.
Over 25,000 Fortinet devices globally have been identified with FortiCloud Single Sign-On (SSO) enabled, creating potential exposure to remote attacks.
CVE-2025-59718 (CVSS 8.2): Involves improper access controls in SSO endpoints, allowing remote attackers to bypass authentication under certain conditions. CVE-2025-59719 (CVSS 7.5): Exploits weak session handling, which could lead to account takeover if combined with phishing or brute-force methods.
Not all devices that are exposed are necessarily vulnerable. Factors such as patch status, configuration specifics, and network segmentation are crucial. The researchers emphasize verifying FortiCloud SSO configurations and applying available patches.
Fortinet has provided fixes in its December 2025 firmware updates, including FortiOS versions 7.4.4 and 7.2.9, recommending the disabling of public SSO exposure where feasible.
Product Affected Versions Fixed Version
FortiOS 7.6 7.6.0 – 7.6.3 7.6.4+ FortiOS 7.4 7.4.0 – 7.4.8 7.4.9+ FortiOS 7.2 7.2.0 – 7.2.11 7.2.12+ FortiOS 7.0 7.0.0 – 7.0.17 7.0.18+ FortiProxy 7.6 7.6.0 – 7.6.3 7.6.4+ FortiProxy 7.4 7.4.0 – 7.4.10 7.4.11+ FortiProxy 7.2 7.2.0 – 7.2.14 7.2.15+ FortiProxy 7.0 7.0.0 – 7.0.21 7.0.22+ FortiSwitchManager 7.2 7.2.0 – 7.2.6 7.2.7+ FortiSwitchManager 7.0 7.0.0 – 7.0.5 7.0.6+ FortiWeb 8.0 8.0.0 8.0.1+ FortiWeb 7.6 7.6.0 – 7.6.4 7.6.5+ FortiWeb 7.4 7.4.0 – 7.4.9 7.4.10+
Organizations are advised to restrict FortiCloud access to VPN-only or private IPs, enable multi-factor authentication (MFA), and monitor logs for unusual SSO activity. Regular scans with tools like Shodan are also recommended, along with utilizing Fortinet's support portal for specific assessments.
Based on reporting by Cyber Security News.
