Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Vulnerability

## Cybersecurity: FortiCloud SSO Vulnerability Exploitation

Cybersecurity: FortiCloud SSO Vulnerability Exploitation

Fortinet has confirmed the active exploitation of a FortiCloud SSO authentication bypass vulnerability. This new automated campaign targets even fully patched FortiGate devices.

On January 15, 2026, cybersecurity firm Arctic Wolf observed attacks involving rapid configuration exfiltration and persistence through generic admin accounts. Fortinet disclosed two critical vulnerabilities in December 2025, identified as CVE-2025-59718 and CVE-2025-59719 (FG-IR-25-647). These vulnerabilities enable unauthenticated attackers to bypass SSO authentication using crafted SAML messages when FortiCloud SSO is enabled. Affected products include FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, allowing admin access without credentials.

Fortinet's PSIRT advisory provides details on vulnerable versions and solutions:

FortiOS 7.6: Versions 7.6.0 through 7.6.3, solution: 7.6.4 or above FortiOS 7.4: Versions 7.4.0 through 7.4.8, solution: 7.4.9 or above FortiOS 7.2: Versions 7.2.0 through 7.2.11, solution: 7.2.12 or above FortiProxy 7.2: Versions 7.2.0 through 7.2.14, solution: 7.2.15 or above FortiSwitchManager 7.2: Versions 7.2.0 through 7.2.6, solution: 7.2.7 or above

Reports confirm exploitation on versions 7.4.9, 7.4.10, and 7.6.x, with fixes scheduled for future releases.

Arctic Wolf telemetry indicates highly automated attacks, similar to activity in December 2025. Threat actors utilize malicious SSO logins, exfiltrate configurations via the GUI for offline credential cracking, and create persistence accounts granting VPN access. Incidents occur within seconds, targeting internet-exposed devices; over 25,000 devices had SSO enabled according to previous scans.

Type IOC Context

User Account cloud-noc@mail[.]io SSO login

User Account cloud-init@mail[.]io SSO login, config exfil

Fortinet has confirmed the active exploitation of a FortiCloud SSO authentication bypass vulnerability.
Madison Drake · Thehackingpost

IP Address 104.28.244[.]115 Cloudflare IP

IP Address 104.28.212[.]114 Intrusions

IP Address 37.1.209[.]19 Third-party observed

IP Address 217.119.139[.]50 Intrusions

Persistence Acct audit, backup, itadmin Local admin creation

Persistence Acct secadmin, support Local admin creation

Advertisement

Persistence Acct remoteadmin, helpdesk Local admin creation

Search logs for SSO successes from these IPs/users and "Add system.admin" events.

Fortinet recommends the following immediate actions:

Disable FortiCloud SSO using the command: config system global set admin-forticloud-sso-login disable end

Implement local-in policies to restrict admin access: config firewall local-in-policy edit 1 set intf "port1" set srcaddr "10.10.10.0" # Trusted subnet set dstaddr "all" set service "HTTPS" set schedule "always" next end

Consider compromised devices as fully owned:

Upgrade to the latest firmware (e.g., 7.6.x) Restore clean configurations Rotate all credentials, including LDAP/AD Audit VPN settings

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories