FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) — Threadlinqs Intelligence
As of 2026-07-18, FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0205 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-18 · revalidated 1× · latest source
Attribution: N/A · FINANCIAL
Active exploitation campaign chaining three critical FortiGate SSO authentication bypass vulnerabilities to gain unauthenticated admin access to FortiGate firewalls, extract device configurations
An ongoing exploitation campaign targets Fortinet FortiGate next-generation firewall appliances through a chain of three critical SSO authentication bypass vulnerabilities. The campaign leverages CVE-2025-59718 and CVE-2025-59719 (CVSS 9.1, CWE-347 — Improper Verification of Cryptographic Signature) disclosed December 2025, and CVE-2026-24858 (CVSS 9.8, CWE-288 — Authentication Bypass Using an Alternate Path or Channel) disclosed January 2026.
CVE-2025-59718 affects FortiOS, FortiProxy, and FortiSwitchManager, while CVE-2025-59719 affects FortiWeb. Both vulnerabilities allow unauthenticated attackers to bypass FortiCloud Single Sign-On (SSO) authentication by submitting specially crafted SAML messages, granting administrative access without valid credentials. The FortiCloud SSO feature, while disabled by factory default, is automatically enabled when devices are registered to FortiCare via the GUI unless explicitly opted out, significantly expanding the attack surface across registered deployments.
CVE-2026-24858 is a net-new vulnerability (not a patch bypass) that allows attackers with a FortiCloud account and a registered device to authenticate to devices registered under other accounts. Organizations that fully patched CVE-2025-59718/59719 remained vulnerable to CVE-2026-24858. Shadowserver identified nearly 10,000 Fortinet instances with FortiCloud SSO enabled globally, with approximately 25% located in the United States.
SentinelOne documented two detailed intrusion incidents spanning November 2025 through February 2026:
Incident 1 (November 2025 – February 2026): Attackers exploited the SSO bypass to extract FortiGate configurations via the 'show full-configuration' command, decrypting reversible encryption to harvest embedded LDAP service account credentials (notably the 'fortidcagent' account). They created a local admin account named 'support' with four firewall policies enabling all-zone traversal. Using the compromised service account, attackers exploited the default Active Directory mS-DS-MachineAccountQuota attribute (which allows standard users to join up to 10 workstations) to enroll rogue workstations (WIN-X8WRBOSK0OF, WIN-YRSXLEONJY2, WIN-1J7L3SQSTMS) into the domain. Network reconnaissance was conducted using SoftPerfect Network Scanner, and password spraying attacks were launched from the FortiGate IP itself.
Incident 2 (Late January 2026): Within 10 minutes of creating a backdoor account 'ssl-admin', attackers logged into multiple servers using Domain Administrator credentials via Network (Type 3) and RDP (Type 10) sessions. They deployed Pulseway and MeshAgent RMM tools for persistence, hiding MeshAgent via registry modification (SystemComponent=1) and creating scheduled tasks (JavaMainUpdate for Pulseway, MeshUserTask for MeshAgent). DLL side-loading was performed via spoofed Java executable names. The attackers extracted NTDS.dit and SYSTEM registry hive via Volume Shadow Copy (WMIC), compressed with makecab, and exfiltrated within an 8-minute window before deleting artifacts.
C2 infrastructure included domains ndibstersoft.com and neremedysoft.com, with Cloudflare-hosted callback at 172.67.196.232:443. Payloads were staged via AWS S3 (fastdlvrss.s3.us-east-1.amazonaws.com) and Google Cloud Storage.
---
**Revalidated on 2026-03-12**
UPDATE (2026-03-12 Revalidation): The campaign has significantly escalated beyond the two SentinelOne-documented incidents. Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor used CyberStrikeAI — an open-source AI-native offensive security platform written in Go — to automate mass scanning and exploitation of FortiGate appliances, compromising 600+ devices across 55 countries in approximately five weeks. CyberStrikeAI was built by a Chinese developer (alias Ed1s0nZ) with documented ties to China's CNNVD (operated by CNITSEC under MSS oversight), evidenced by a CNNVD 2024 Vulnerability Reward Program Level 2 award that was
Weaknesses (CWE)
CWE-347, CWE-288, CWE-326, CWE-916
Target sectors: government, financial, healthcare, technology, critical-infrastructure, defense, education, energy
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-59718, CVE-2025-59719, CVE-2026-24858, T1190, T1078, T1059, T1136, T1098, T1053, T1574, T1078, T1112, T1036