Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
These articles are AI-generated summaries. Please check the original sources for full details.
Automated FortiGate Attacks Exploit FortiCloud SSO
Arctic Wolf has identified a new wave of automated attacks targeting Fortinet FortiGate devices, beginning January 15, 2026. These attacks exploit vulnerabilities (CVE-2025-59718 and CVE-2025-59719) in FortiCloud Single Sign-On (SSO) to gain unauthorized access and modify firewall settings.
Why This Matters
Ideal network security models assume controlled access and integrity of firewall configurations, but vulnerabilities like these demonstrate a critical gap. Successful exploitation allows attackers to establish persistence, grant VPN access, and steal sensitive firewall configurations, potentially compromising entire network infrastructures. The scale of impacted devices and potential damage from a widespread breach is significant, representing a substantial financial and reputational risk.
Key Insights
- SAML Bypass: Exploitation relies on unauthenticated bypass of SSO login authentication via crafted SAML messages.
- Automated Activity: Events occur within seconds of each other, indicating the use of automated tools for rapid exploitation.
- Account Creation: Attackers create generic accounts (e.g., “secadmin,” “itadmin”) for persistence post-exploitation.
Practical Applications
- Use Case: Organizations utilizing FortiGate with FortiCloud SSO are at risk of unauthorized configuration changes and data exfiltration.
- Pitfall: Relying solely on patching without disabling the vulnerable “admin-forticloud-sso-login” setting leaves systems exposed.
References:
Continue reading
Next article
Cisco Patches Actively Exploited Zero-Day (CVE-2026-20045) in Unified CM and Webex
Related Content
Fortinet Firewalls Hit With Malicious Configuration Changes
Compromised FortiGate devices are experiencing automated malicious SSO logins and configuration data theft.
Fortinet Confirms Active FortiCloud SSO Bypass on Patched Firewalls
Fortinet confirms ongoing exploitation of a FortiCloud SSO bypass (CVE-2025-59718/CVE-2025-59719) even on fully patched FortiGate devices, highlighting SAML vulnerability risks.
FortiGate Appliances Targeted to Steal LDAP Credentials and Breach Networks
Threat actors are exploiting FortiGate NGFW vulnerabilities to extract configuration files and decrypt LDAP credentials for Active Directory access.