logo

Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access

ID: dd83c133-311c-55ee-9521-6264064e82f4

STIX ID: report--dd83c133-311c-55ee-9521-6264064e82f4

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Guru Baran

...
...

### Executive Summary A critical FortiGate Single Sign-On (SSO) vulnerability (CVE-2025-59718) is being actively exploited to create persistent local administrator accounts on internet-exposed devices; exploitation has been observed on FortiOS 7.4.9/7.4.10 and similar branches, with reports of over 25,000 devices potentially exposed. Fortinet is investigating, scheduled fixes are referenced for upcoming releases, and immediate mitigations (disable FortiCloud SSO, audit logs, network segmentation, and patching) are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.