logo

Fortinet confirms critical FortiCloud auth bypass not fully patched

ID: ec8db9ac-9337-5b69-9d3a-edb6f82f9841

STIX ID: report--ec8db9ac-9337-5b69-9d3a-edb6f82f9841

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-23

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet confirmed active exploitation of a critical FortiCloud SSO authentication bypass (CVE-2025-59718) that has been used in automated campaigns to create admin accounts and steal firewall configurations, including on devices reported as fully patched. Customers and researchers observed matching IOCs and rapid post-exploitation activity; Fortinet is developing a full fix while advising immediate mitigations (disable FortiCloud SSO, restrict admin access, rotate credentials) and authorities (CISA) have added the CVE to their known-exploited list.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.