Fortinet has confirmed that attackers are actively bypassing a December patch for a critical FortiCloud single sign-on (SSO) authentication flaw after customers reported suspicious logins on devices supposedly fully up to date. In a new advisory, Fortinet said it had identified a fresh attack path being used to abuse SAML-based SSO in FortiOS, even on systems that had already applied the vendor's earlier fix. The disclosure follows reports earlier this week that FortiGate firewalls were quietly reconfigured via compromised SSO accounts, with attackers altering firewall settings, creating backdoor admin users, and exfiltrating configuration files. Arctic Wolf said the campaign kicked off around January 15, with attackers spinning up VPN-enabled accounts and ripping out firewall configuration files in a matter of seconds – behavior strongly suggesting automation rather than careful, hands-on-keyboard work. The security firm added that the activity closely mirrors incidents it observed back in December, in the wake of Fortinet's disclosure of the supposedly patched SSO authentication bypass flaw. "Recently, a small number of customers reported unexpected login activity occurring on their devices, which appeared very similar to the previous issue," said Fortinet chief information security officer Carl Windsor. "However, in the last 24 hours, we have identified a number of cases where the exploit was to a device that had been fully upgraded to the latest release at the time of the...
Fortinet admits FortiGate SSO bug still exploitable despite December patch
The Register
·Carly Page
·Published Jan 23, 2026
·Updated
Affected Software
1 affected component
Fortinet FortiOS<latest
Frequently Asked Questions
1
What critical security flaw is discussed in the article?
The article discusses a critical single sign-on (SSO) authentication vulnerability in FortiGate products.
2
Has Fortinet released a patch for the SSO vulnerability?
Yes, Fortinet released a patch in December, but the vulnerability remains exploitable.
3
What are the signs of exploitation reported by customers?
Customers reported suspicious logins on devices that were supposedly up to date.
4
Which products are primarily affected by the security flaw?
The security flaw primarily affects Fortinet FortiOS.
5
What are the risks associated with the unpatched vulnerability?
The unpatched vulnerability poses a risk of unauthorized access to FortiGate devices.