Fortinet has disclosed two critical vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager products. These flaws stem from improper verification of cryptographic signatures in the FortiCloud SSO login feature, allowing unauthenticated attackers to bypass authentication by sending crafted SAML response messages. The vulnerabilities are remotely exploitable and impact a wide range of product versions, but the FortiCloud SSO login is not enabled by default unless the device is registered to FortiCare and the feature is explicitly activated.
Administrators are strongly advised to disable the FortiCloud SSO login feature if enabled and to apply the latest security updates provided by Fortinet. Additional mitigations include using the device's GUI or CLI to turn off administrative login via FortiCloud SSO. Fortinet also addressed other vulnerabilities in the same advisory, but the authentication bypass flaws pose the most immediate risk due to their critical severity and potential for exploitation in the wild. Organizations should prioritize patching and review their FortiCloud SSO configurations to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-09, the Canadian Centre for Cyber Security highlighted Fortinet's advisories and urged users and administrators to review them and apply the necessary updates. The alert emphasized the risk of authentication bypass and stated that no active exploitation had been reported as of that date.
Alongside the patches, Fortinet advised administrators to apply updates immediately, review FortiCloud SSO settings, and disable FortiCloud SSO login until systems are updated. Advisories also noted additional fixes for CVE-2025-59808 and CVE-2025-64471.
On 2025-12-09, Fortinet released security advisories and patches for critical vulnerabilities CVE-2025-59718 and CVE-2025-59719 affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. The flaws allow FortiCloud SSO authentication bypass via crafted SAML messages when the FortiCloud SSO login feature is enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcebleepingcomputer.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.