Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. Fortinet noted on December 9th, when it patched the security flaw tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb), that the vulnerable FortiCloud SSO login feature is not enabled until admins register the device with the company's FortiCare support service. As cybersecurity company Arctic Wolf reported on Monday, the vulnerability is now actively exploited to compromise admin accounts via malicious single sign-on (SSO) logins. Threat actors are abusing it in vulnerable products via a maliciously crafted SAML message to gain admin-level access to the web management interface and download system configuration files. These sensitive files expose potentially vulnerable interfaces, hashed passwords that attackers may crack, internet-facing services, network layouts, and firewall policies. Today, Shadowserver said it's tracking over 25,000 IP addresses with a FortiCloud SSO fingerprint, more than 5,400 in the United States and nearly 2,000 in India. However, there is currently no information regarding how many have been secured against attacks exploiting the CVE-2025-59718/CVE-2025-59719 vulnerability. Macnica threat researcher Yutaka Sejiyama also told BleepingComputer that his scans returned over 30,000 Fortinet devices with Forti...
Over 25,000 FortiCloud SSO devices exposed to remote attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 19, 2025
·Updated
Affected Software
4 affected components
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiSwitchManager
Fortinet FortiWeb
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exposure of over 25,000 FortiCloud SSO devices to remote attacks due to a critical authentication bypass vulnerability.
2
What security implications are discussed?
The article highlights the serious risk of remote attacks on vulnerable FortiCloud devices, which could lead to unauthorized access and data breaches.
3
What products or software are affected?
The affected products include Fortinet FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb.
4
Who identified the exposed devices, and what is their role?
The exposure was identified by internet security watchdog Shadowserver, which monitors network security threats.
5
What actions should users of these devices take?
Users should immediately secure their FortiCloud SSO devices by applying available patches and ensuring they have the latest security updates.