FortiCloud SSO Authentication Bypass Exploited

Related

Python-Based PyRAT Targets Windows and Linux Systems

What happened K7 Security Labs researchers identified a Python-based remote...

Exposed Open Directory Leaks BYOB Malware Framework

What happened An exposed open directory was discovered hosting a...

BlackIce Red Teaming Toolkit Released for AI Security Testing

What happened Databricks introduced BlackIce, a containerized toolkit designed to...

FortiCloud SSO Authentication Bypass Exploited

What happened An authentication bypass vulnerability affecting FortiCloud Single Sign-On...

31.4 Tbps DDoS Attack Sets New Record

What happened A distributed denial-of-service campaign reached a peak traffic...

Share

What happened

An authentication bypass vulnerability affecting FortiCloud Single Sign-On was confirmed to be actively exploited. The flaw allows attackers with a FortiCloud account to authenticate to unrelated Fortinet devices when SSO is enabled. The vulnerability was added to the Known Exploited Vulnerabilities catalog.

Who is affected

Fortinet devices with FortiCloud SSO enabled are directly exposed to exploitation.

Why CISOs should care

Authentication bypass vulnerabilities undermine administrative access controls across network security infrastructure.

3 practical actions

  • Inventory FortiCloud SSO usage. Identify enabled systems.
  • Apply available patches. Update affected products.
  • Review authentication logs. Monitor for anomalous access activity.