• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-confirms-critical-forticloud-auth-bypass-not-fully-patched/

Fortinet confirms critical FortiCloud auth bypass not fully patched

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 23, 2026
·
Updated

Days after admins began reporting that their fully patched firewalls are being hacked, Fortinet confirmed it's working to fully address a critical FortiCloud SSO authentication bypass vulnerability that should have already been patched since early December. This comes after a wave of reports from Fortinet customers about threat actors exploiting a patch bypass for the CVE-2025-59718 vulnerability to compromise fully patched firewalls. Cybersecurity company Arctic Wolf said on Wednesday that the campaign began on January 15, with attackers creating accounts with VPN access and stealing firewall configurations within seconds, in what appear to be automated attacks. It also added that the attacks are very similar to incidents it documented in December, following the disclosure of the CVE-2025-59718 critical vulnerability in Fortinet products. On Thursday, Fortinet finally confirmed these reports, stating that ongoing CVE-2025-59718 attacks match December's malicious activity and that it's now working to fully patch the flaw. Affected Fortinet customers have also shared logs showing that the attackers created admin users after an SSO login from cloud-init@mail.io on IP address 104.28.244.114, which match indicators of compromise detected by Arctic Wolf while analyzing ongoing FortiGate attacks and December in-the-wild exploitation, as well as those shared by Fortinet on Thursday. "Recently, a small number of customers reported unexpected login activity occurring on their devices...

Read full article

Affected Software

2 affected components
Fortinet FortiCloud SSO>=1.0
Fortinet FortiGate>=1.0

Frequently Asked Questions

1

Which Fortinet systems are affected by the ongoing attacks?

The reports concern Fortinet firewalls using FortiCloud SSO, including fully patched devices. Attackers are exploiting a patch bypass related to CVE-2025-59718.

2

What attacker activity has been observed?

Attackers have created accounts with VPN access, stolen firewall configurations, and created admin users after an SSO login. Arctic Wolf said these actions occurred within seconds and appear to be automated.

3

When did the current campaign begin, and is it related to earlier activity?

Arctic Wolf said the campaign began on January 15. Fortinet said the ongoing attacks match malicious activity seen in December after CVE-2025-59718 was disclosed.

4

Has Fortinet fully fixed the authentication bypass?

No. Fortinet confirmed that it is still working to fully patch CVE-2025-59718 after reports that attackers were compromising fully patched firewalls.

5

What indicators were reported in affected customers' logs?

Affected customers shared logs showing admin-user creation following an SSO login from cloud-init@mail.io and IP address 104.28.2….

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203