Days after admins began reporting that their fully patched firewalls are being hacked, Fortinet confirmed it's working to fully address a critical FortiCloud SSO authentication bypass vulnerability that should have already been patched since early December. This comes after a wave of reports from Fortinet customers about threat actors exploiting a patch bypass for the CVE-2025-59718 vulnerability to compromise fully patched firewalls. Cybersecurity company Arctic Wolf said on Wednesday that the campaign began on January 15, with attackers creating accounts with VPN access and stealing firewall configurations within seconds, in what appear to be automated attacks. It also added that the attacks are very similar to incidents it documented in December, following the disclosure of the CVE-2025-59718 critical vulnerability in Fortinet products. On Thursday, Fortinet finally confirmed these reports, stating that ongoing CVE-2025-59718 attacks match December's malicious activity and that it's now working to fully patch the flaw. Affected Fortinet customers have also shared logs showing that the attackers created admin users after an SSO login from cloud-init@mail.io on IP address 104.28.244.114, which match indicators of compromise detected by Arctic Wolf while analyzing ongoing FortiGate attacks and December in-the-wild exploitation, as well as those shared by Fortinet on Thursday. "Recently, a small number of customers reported unexpected login activity occurring on their devices...
Fortinet confirms critical FortiCloud auth bypass not fully patched
Affected Software
Frequently Asked Questions
Which Fortinet systems are affected by the ongoing attacks?
The reports concern Fortinet firewalls using FortiCloud SSO, including fully patched devices. Attackers are exploiting a patch bypass related to CVE-2025-59718.
What attacker activity has been observed?
Attackers have created accounts with VPN access, stolen firewall configurations, and created admin users after an SSO login. Arctic Wolf said these actions occurred within seconds and appear to be automated.
When did the current campaign begin, and is it related to earlier activity?
Arctic Wolf said the campaign began on January 15. Fortinet said the ongoing attacks match malicious activity seen in December after CVE-2025-59718 was disclosed.
Has Fortinet fully fixed the authentication bypass?
No. Fortinet confirmed that it is still working to fully patch CVE-2025-59718 after reports that attackers were compromising fully patched firewalls.
What indicators were reported in affected customers' logs?
Affected customers shared logs showing admin-user creation following an SSO login from cloud-init@mail.io and IP address 104.28.2….