Fortinet confirms critical FortiCloud auth bypass not fully patched
ID: ec8db9ac-9337-5b69-9d3a-edb6f82f9841
STIX ID: report--ec8db9ac-9337-5b69-9d3a-edb6f82f9841
Feed Name: Bleeping Computer
Fortinet confirmed active exploitation of a critical FortiCloud SSO authentication bypass (CVE-2025-59718) that has been used in automated campaigns to create admin accounts and steal firewall configurations, including on devices reported as fully patched. Customers and researchers observed matching IOCs and rapid post-exploitation activity; Fortinet is developing a full fix while advising immediate mitigations (disable FortiCloud SSO, restrict admin access, rotate credentials) and authorities (CISA) have added the CVE to their known-exploited list.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
