Analysis of Single Sign-On Abuse on FortiOS

2026-03-04T20:42:41Z621fa1b056bcf4825154c103608c8d25fc19517aa880f95dd288a064ebe1ecb2
CVE-2022-39952CVE-2023-27997FG-IR-19-283FG-IR-23-097exploitationfortigatefortinetfortiosincident-responseiotcpatchingpsirtresponsible-disclosuressl-vpnssothreat-actor

What happened

Collection of Fortinet PSIRT blog posts analyzing multiple incidents and exploitation trends impacting Fortinet products. Topics include observed single sign-on (SSO) abuse on FortiOS, post‑exploitation techniques used by threat actors, observed abuse of advisory FG-IR-19-283, threat actor data postings claiming compromised FortiGate configs/VPN credentials, and the exploitation of known N‑day vulnerabilities. The feed includes references to Fortinet advisories and CVE-2023-27997 (noted as CVSS Critical) and CVE-2022-39952, guidance for administrators to confirm impact and mitigate risk, IoCs,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
fortinet_blog
Record identifier
621fa1b056bcf4825154c103608c8d25fc19517aa880f95dd288a064ebe1ecb2
Enrichment time
2026-03-04T20:42:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Analysis of Single Sign-On Abuse on FortiOS · Baitaphish