logo

Fortinet admins report patched FortiGate firewalls getting hacked

ID: 2789d8e0-00cf-55f2-9ecb-dfc60459b3cb

STIX ID: report--2789d8e0-00cf-55f2-9ecb-dfc60459b3cb

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-01-21

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet customers are reporting active exploitation of a FortiCloud SSO authentication bypass (CVE-2025-59718) that appears not fully mitigated in some FortiOS releases (notably 7.4.9 and reportedly 7.4.10), with attackers using crafted SAML messages to create admin accounts; Shadowserver found thousands of devices with FortiCloud SSO enabled and CISA has added the CVE to its known exploited vulnerabilities list, while Fortinet plans additional patches and administrators are advised to disable FortiCloud SSO until fixes are confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.