Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

FortiOS, FortiWeb, and FortiProxy Vulnerability Lets Attackers Bypass FortiCloud SSO Authentication

## Cybersecurity: Fortinet Security Advisory

Cybersecurity: Fortinet Security Advisory

Fortinet has released a security advisory concerning a critical vulnerability affecting its FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager product lines. This vulnerability, identified as an Improper Verification of Cryptographic Signature (CWE-347), allows an unauthenticated attacker to bypass FortiCloud Single Sign-On (SSO) login authentication.

The issue arises from the device's failure to correctly verify signatures within SAML messages. Exploitation could enable unauthorized administrative access through a crafted SAML message. This vulnerability was internally discovered by Fortinet Product Security team members Yonghui Han and Theo Leleu and publicly disclosed on Tue, Dec 9, 2025.

Though the FortiCloud SSO login feature is disabled by default, it remains a significant vulnerability in operational environments. When a device is registered to FortiCare via the graphical user interface (GUI), the "Allow administrative login using FortiCloud SSO" toggle is enabled by default. Unless explicitly disabled by the administrator, the device becomes susceptible to this bypass immediately.

The issue arises from the device's failure to correctly verify signatures within SAML messages.
Thomas Blake · Thehackingpost

Fortinet advises customers to upgrade to the latest versions listed below. For organizations unable to patch immediately, a temporary workaround is available: disabling the FortiCloud login feature.

Product Affected Versions Remediation

Advertisement

FortiOS 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above FortiOS 7.4 7.4.0 through 7.4.8 Upgrade to 7.4.9 or above FortiOS 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above FortiOS 7.0 7.0.0 through 7.0.17 Upgrade to 7.0.18 or above FortiOS 6.4 Not affected None FortiProxy 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above FortiProxy 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above FortiProxy 7.2 7.2.0 through 7.2.14 Upgrade to 7.2.15 or above FortiProxy 7.0 7.0.0 through 7.0.21 Upgrade to 7.0.22 or above FortiSwitchManager 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above FortiSwitchManager 7.0 7.0.0 through 7.0.5 Upgrade to 7.0.6 or above FortiWeb 8.0 8.0.0 Upgrade to 8.0.1 or above FortiWeb 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above FortiWeb 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories