The Hacker News
Read post

Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls

Fortinet confirmed active exploitation of a FortiCloud SSO authentication bypass affecting fully patched FortiGate firewalls. The new attack path bypasses previous patches for CVE-2025-59718 and CVE-2025-59719 through crafted SAML messages. Attackers create persistence accounts (cloud-noc@mail.io, cloud-init@mail.io), grant VPN access, and exfiltrate firewall configurations. Fortinet recommends restricting administrative access via local-in policies and disabling FortiCloud SSO logins, noting the issue affects all SAML SSO implementations.

    #security#cyber#authentication#fortinet
Jan 23•2m read time•From thehackernews.com
Post cover image
50 Impressions
The Hacker News's image
The Hacker News

The Tidyverse Blog offers insights, tutorials, and updates on the Tidyverse, a collection of R packa...

2.3K Followers

•

1.7K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard