logo

Fortinet admits FortiGate SSO bug still exploitable despite December patch

ID: 2b995a7d-d2f6-530c-8b5f-321cd35da33c

STIX ID: report--2b995a7d-d2f6-530c-8b5f-321cd35da33c

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-01-23

Date Updated: 2026-04-26

Author: Carly Page

...
...

Fortinet has confirmed attackers are actively abusing a SAML-based FortiCloud SSO authentication bypass—including against systems reportedly patched in December—allowing rapid, automated reconfiguration of FortiGate devices, creation of backdoor admin users, and exfiltration of configuration files. Fortinet is investigating a new attack path, warns the issue affects SAML SSO broadly, and advises customers to monitor authentication logs, restrict management interfaces, and watch for unexpected administrative changes while a remedial fix is developed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.