Fortinet warns of active FortiCloud SSO bypass affecting updated devices
ID: 745066f0-928d-500f-8915-b384ae58e905
STIX ID: report--745066f0-928d-500f-8915-b384ae58e905
Feed Name: Security Affairs
Fortinet confirmed active attacks bypassing FortiCloud SSO—including on fully patched devices—where threat actors automate firewall configuration changes, create persistent admin accounts, enable VPN access, and exfiltrate device configurations. Arctic Wolf observed a cluster of automated activity since January 15, 2026, and earlier exploitation was noted in December 2025 following disclosure of two critical SSO bypass CVEs; Fortinet is developing a fix, has published IOCs, and recommends restricting admin access and temporarily disabling FortiCloud SSO as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
