logo

Over 25,000 FortiCloud SSO devices exposed to remote attacks

ID: ca881072-6fcc-5995-b39c-6d94409cba99

STIX ID: report--ca881072-6fcc-5995-b39c-6d94409cba99

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Shadowserver, Arctic Wolf, and other researchers report active exploitation of a Fortinet FortiCloud SSO authentication-bypass (CVE-2025-59718 / CVE-2025-59719) that allows attackers to craft SAML messages to obtain admin web-GUI access and exfiltrate system configs; scans show >25,000 exposed devices (over 5,400 in the U.S.), and CISA has added the flaw to its actively exploited vulnerabilities catalog and mandated rapid patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.