Fortinet Admins Report Active Exploits on “Fixed” FortiOS 7.4.9 Firmware
ID: 1543ceb7-2fe6-5691-a928-4bcbc48c04eb
STIX ID: report--1543ceb7-2fe6-5691-a928-4bcbc48c04eb
Feed Name: The Cyber Express
Threat Score
**Executive summary:** Credible community reports indicate active exploitation of Fortinet SSO vulnerability CVE-2025-59718—attackers are forging SAML assertions to bypass authentication on FortiGate devices (including reports against patched 7.4.9 installs), creating local administrator accounts and exporting configurations; recommended immediate mitigation is to disable FortiCloud SSO via CLI and audit SSO logins, new admin creation, and config exports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
