Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

25,000+ FortiCloud SSO-Enabled Systems Vulnerable to Remote Exploitation

The Shadowserver Foundation has identified over 25,000 internet-facing Fortinet devices globally with FortiCloud Single Sign-On (SSO) functionality enabled, raising concerns about potential exposure to critical authentication bypass vulnerabilities.

The Shadowserver Foundation has identified over 25,000 internet-facing Fortinet devices globally with FortiCloud Single Sign-On (SSO) functionality enabled, raising concerns about potential exposure to critical authentication bypass vulnerabilities.

The non-profit security organization recently added fingerprinting capabilities for these systems to its Device Identification reporting service, alerting network administrators to verify their security posture immediately.

Mass Exposure Discovered Through Global Scanning

Shadowserver's latest scan results reveal at least 25,000 IP addresses worldwide hosting Fortinet devices configured with FortiCloud SSO enabled.

While not all exposed systems are necessarily vulnerable, the discovery highlights a significant attack surface that threat actors could exploit.

Organizations receiving exposure notifications from Shadowserver are urged to verify their patch status and implement security updates without delay.

The alert references explicitly CVE-2025-59718 and CVE-2025-59719, two critical authentication bypass vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager products.

Shadowserver's latest scan results reveal at least 25,000 IP addresses worldwide hosting Fortinet devices configured with FortiCloud SSO enabled.
John Mason · Thehackingpost

These flaws carry a CVSS v3 score of 9.1 and allow unauthenticated remote attackers to bypass FortiCloud SSO authentication through specially crafted SAML messages, potentially granting administrative access without credentials.

Security researchers emphasize that exposed FortiCloud SSO implementations create opportunities for unauthorized access to enterprise network infrastructure.

Attackers exploiting these vulnerabilities could gain complete administrative control over affected devices, leading to network compromise, data exfiltration, or deployment of additional malware.

Fortinet customers should immediately verify whether their devices appear in Shadowserver's reporting and confirm patch status.

Advertisement

The vendor has released security updates for affected product versions, and organizations should prioritize upgrading to patched releases.

As a temporary mitigation, administrators can turn off FortiCloud SSO functionality in system settings or via CLI commands until patches are deployed.

The Shadowserver Foundation provides free security scanning reports to network owners worldwide, helping identify vulnerable or misconfigured systems before attackers discover them.

Organizations that have not registered for these notifications should consider doing so to receive timely alerts about exposed infrastructure.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories