Arctic Wolf and multiple Fortinet customers reported ongoing intrusions against Fortinet FortiGate devices involving malicious SSO logins followed by unauthorized configuration changes, including creation of new admin/persistent accounts, granting VPN access, and exfiltration of firewall configurations. Arctic Wolf observed the activity beginning January 15, 2026, describing it as automated and similar to exploitation patterns previously tied to crafted SAML messages when FortiCloud SSO is enabled, consistent with earlier reporting around CVE-2025-59718 and CVE-2025-59719.
Administrators reported compromises occurring even on systems believed to be patched, indicating a patch bypass or incomplete fix for CVE-2025-59718 in FortiOS releases intended to remediate the issue (with claims that FortiOS 7.4.10 still did not fully address the vulnerability). Shared logs described SSO logins (e.g., cloud-init@mail.io) from specific IP infrastructure (e.g., 104.28.244.114) followed by creation of new admin users such as helpdesk, matching the TTPs Arctic Wolf previously documented. Fortinet was reportedly preparing additional FortiOS releases (e.g., 7.4.11, 7.6.6, 8.0.0) to fully remediate, while defenders were advised to consider temporarily disabling the vulnerable SSO functionality pending a confirmed fix.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On January 27, 2026, Fortinet issued advisory FG-IR-26-060 for CVE-2026-24858, a critical FortiCloud SSO authentication bypass affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy when FortiCloud SSO is enabled. The company restored FortiCloud SSO with server-side restrictions that block logins from devices running vulnerable firmware and provided fixed-version guidance and remediation steps.
On January 26, 2026, Fortinet disabled FortiCloud SSO server-side to block ongoing exploitation while a permanent fix was finalized. This emergency action was intended to stop attackers from abusing the authentication path against vulnerable devices.
By January 23, 2026, Fortinet publicly confirmed it was working on a complete fix after reports that prior updates did not fully remediate the issue. The company said additional releases were being prepared and reiterated guidance to disable FortiCloud SSO administrative login and rotate credentials if compromise indicators were present.
Fortinet took server-side action on January 22, 2026 by disabling or locking abused FortiCloud accounts associated with the exploitation. This was an early containment step while the company continued investigating the broader authentication bypass issue.
Alongside its January 22 analysis, Fortinet published indicators of compromise such as suspicious SSO identities, source IPs, and common local admin usernames created after compromise. It advised customers to restrict administrative access with local-in policies, disable FortiCloud SSO as a workaround, and treat affected systems as compromised.
On January 22, 2026, Fortinet said it had identified cases in the prior 24 hours where attacks succeeded against devices fully upgraded to the latest release, indicating a new attack path. The company warned the underlying issue could apply to all SAML SSO implementations, not just FortiCloud SSO, and said it was working on a fix.
Arctic Wolf publicly reported the January 15 attack cluster on January 21, 2026, describing automated SSO logins, configuration exfiltration, and creation of generic persistence accounts. The company also released indicators of compromise and recommended restricting management access and disabling FortiCloud SSO where possible.
By January 21, 2026, multiple Fortinet customers reported malicious FortiCloud SSO logins and rogue admin account creation on devices believed to be fully patched, including systems on FortiOS 7.4.9 and reportedly 7.4.10. These reports raised concerns that the December fix for CVE-2025-59718 was incomplete or bypassed.
A new cluster of highly automated attacks began around January 15, 2026, targeting Fortinet FortiGate devices through SSO-related access. Attackers logged in via FortiCloud SSO, exported firewall configurations, created local admin accounts, and in some cases enabled VPN access for persistence.
CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog and gave U.S. federal agencies one week to apply mitigations. The listing reflected confirmed active exploitation of the Fortinet SSO authentication bypass issue.
Beginning around December 12, 2025, Arctic Wolf observed attackers exploiting the FortiCloud SSO flaws, using malicious SSO logins followed by rapid configuration exports and administrative changes on FortiGate devices. This established that the December vulnerabilities were being actively abused in real environments.
In December 2025, Fortinet disclosed and patched two critical FortiCloud SSO authentication bypass vulnerabilities involving crafted SAML messages, including CVE-2025-59718 and CVE-2025-59719. FortiOS 7.4.9 was presented as the fix for the 7.4 branch, and the issues were tied to FortiCloud SSO being enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcearcticwolf.com
Open sourcecybersecuritynews.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcesecurityonline.info
Open sourcedarkreading.com
Open sourcearcticwolf.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.