Fortinet Confirms Active Exploitation of FortiCloud SSO Bypass Vulnerability
Fortinet has confirmed active exploitation of critical vulnerabilities in the FortiCloud single sign-on (SSO) authentication bypass, affecting several enterprise security appliances.
Fortinet has confirmed active exploitation of critical vulnerabilities in the FortiCloud single sign-on (SSO) authentication bypass, affecting several enterprise security appliances.
The vulnerabilities, identified as CVE-2025-59718 and CVE-2025-59719, were discovered during internal code audits in December 2025. Exploitation attempts have been documented in customer environments.
These vulnerabilities arise from improper verification of cryptographic signatures within FortiCloud SSO implementations affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager devices. If enabled, they allow unauthenticated attackers to bypass login authentication by crafting malicious SAML messages, granting unauthorized administrative access to affected devices.
FortiCloud SSO is not enabled by default. However, it becomes active when administrators register devices with FortiCare without explicitly disabling the "Allow administrative login using FortiCloud SSO" setting.
Fortinet has observed a shift in the exploitation landscape, with reports of suspicious login activity matching initial vulnerability indicators. Notably, exploitation cases have been identified on fully patched systems, suggesting the existence of an undiscovered attack vector beyond the original vulnerability disclosure. Fortinet is actively investigating this new attack methodology and is working on remediations.
The vulnerabilities, identified as CVE-2025-59718 and CVE-2025-59719, were discovered during internal code audits in December 2025.
Security leadership has emphasized that while FortiCloud SSO exploitation is prevalent, the vulnerability affects all SAML-based SSO implementations across vulnerable product versions, indicating broader exposure than initially assessed.
The vulnerability impacts multiple product lines across various firmware versions. FortiOS versions 7.0 through 7.6 are affected, with solutions available from version 7.0.18 to 7.6.4 and above, depending on the branch. FortiProxy versions 7.0 through 7.6 require updates to 7.0.22, 7.2.15, 7.4.11, or 7.6.4 respectively. FortiWeb 7.4, 7.6, and 8.0 require patching, while FortiSwitch Manager versions 7.0 and 7.2 need upgrades to 7.0.6 and 7.2.7 respectively.
For organizations unable to patch immediately, Fortinet recommends disabling FortiCloud SSO login functionality via System Settings or CLI command: config system global , followed by set admin-forticloud-sso-login disable , then end . This mitigation temporarily eliminates the authentication bypass vector while patches are deployed.
The confirmed exploitation, newly discovered attack paths, and multi-product impact create an elevated risk for enterprises using Fortinet infrastructure. Organizations should prioritize vulnerability scanning, validate patch deployment status, and ensure FortiCloud SSO is either disabled or updated to patched releases.
Network defenders are advised to monitor for anomalous administrative login events, especially from unexpected geographic origins or times inconsistent with normal operations. Fortinet administrators must treat firmware updates as critical and ensure baseline security controls are enforced until patches are universally deployed.
This incident highlights the importance of consistent SSO security across hybrid security architectures and the ongoing threat posed by authentication bypass vulnerabilities in enterprise appliances.
For more information, visit Fortinet's official blog .
Based on reporting by GBHackers.
