Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access
A vulnerability in Fortinet's Single Sign-On (SSO) feature for FortiGate firewalls, identified as CVE-2025-59718 , is currently being exploited.
A vulnerability in Fortinet's Single Sign-On (SSO) feature for FortiGate firewalls, identified as CVE-2025-59718 , is currently being exploited.
Attackers are using this vulnerability to create unauthorized local admin accounts, thereby gaining full administrative access to affected devices exposed to the internet.
Reports of similar attack patterns have prompted an investigation by Fortinet's Product Security Incident Response Team (PSIRT).
CVE-2025-59718 impacts the FortiCloud SSO login mechanism in FortiOS, allowing remote attackers to authenticate using malicious SSO logins and bypass standard controls.
This flaw enables privilege escalation on firewalls using SAML or FortiCloud SSO for admin authentication, even after patches have been applied. Although no CVSS score is available yet, the real-world impact is significant: attackers can create backdoor accounts, such as "helpdesk," with full system privileges. The devices must be internet-facing with SSO enabled to be exploited.
As of now, more than 25,000 Fortinet devices have been identified as publicly accessible online, many with the FortiCloud SSO feature activated. Shadowserver's discovery highlights the extent of exposure as of mid-December.
FortiOS Version Vulnerability Status Fix Availability
A vulnerability in Fortinet's Single Sign-On (SSO) feature for FortiGate firewalls, identified as CVE-2025-59718 , is currently being exploited.
7.4.9 Vulnerable (exploited) 7.4.11 (scheduled)
7.4.10 Vulnerable (not fixed) 7.4.11 (scheduled)
7.6.x Vulnerable 7.6.6 (scheduled)
8.0.x Vulnerable (pre-release) 8.0.0 (scheduled)
For further details, please refer to Fortinet's advisory.
To mitigate the risk of exploitation, disable FortiCloud SSO logins using the following CLI commands:
config system global set admin-forticloud-sso-login disable end
This action prevents SSO-based attacks without affecting local or SAML authentication. It is advisable to re-enable SSO post-patch. Fortinet recommends applying this workaround immediately, particularly for internet-exposed firewalls.
Audit Logs: Monitor for suspicious SSO logins and new admin accounts such as "helpdesk." Network Segmentation: Limit admin access and enforce Local-In policies. Monitoring: Use SIEM to track admin changes and scan for indicators of compromise (IOCs) such as matching IPs/logins. Patching: Upgrade to fixed versions once available and test these updates in a staging environment. Enterprise Response: If a compromise is detected, rotate credentials, isolate affected devices, and contact Fortinet support.
Fortinet plans to release advisories soon. This incident highlights the risks associated with SSO in firewall configurations, emphasizing the importance of disabling unnecessary features and maintaining vigilant monitoring.
Based on reporting by Cyber Security News.
