Over 25,000 FortiCloud SSO devices exposed to remote attacks
ID: ca881072-6fcc-5995-b39c-6d94409cba99
STIX ID: report--ca881072-6fcc-5995-b39c-6d94409cba99
Feed Name: Bleeping Computer
Threat Score
Shadowserver, Arctic Wolf, and other researchers report active exploitation of a Fortinet FortiCloud SSO authentication-bypass (CVE-2025-59718 / CVE-2025-59719) that allows attackers to craft SAML messages to obtain admin web-GUI access and exfiltrate system configs; scans show >25,000 exposed devices (over 5,400 in the U.S.), and CISA has added the flaw to its actively exploited vulnerabilities catalog and mandated rapid patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
