Fortinet has disclosed and patched two critical authentication bypass vulnerabilities, identified as CVE-2025-59718 and CVE-2025-59719, affecting multiple products including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. These flaws, rated with a CVSS score of 9.1, stem from improper verification of cryptographic signatures in the FortiCloud SSO login process. An unauthenticated attacker could exploit these vulnerabilities by sending a crafted SAML message, potentially gaining unauthorized administrative access if FortiCloud SSO is enabled. By default, FortiCloud SSO is disabled, but it is automatically enabled during FortiCare registration unless the administrator explicitly disables the relevant toggle.
Fortinet has released fixed versions for all affected products and strongly recommends that organizations upgrade immediately. As a temporary mitigation, disabling the FortiCloud SSO login feature is advised until the upgrade can be completed. There is currently no evidence of exploitation in the wild, and no public proof-of-concept code is available, but the history of threat actors targeting Fortinet products underscores the urgency of patching. The vulnerabilities impact a range of versions across FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, with unaffected versions and upgrade paths detailed in the advisories.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By 2025-12-11, follow-on reporting said national CERTs and major vulnerability scanners had highlighted the two Fortinet flaws for immediate remediation because successful exploitation could grant full administrative access. This reflected broader defensive escalation after the vendor disclosure.
In its advisory, Fortinet stated there was no known in-the-wild exploitation and no public proof-of-concept at the time of disclosure. The company recommended upgrading to fixed versions and temporarily disabling FortiCloud SSO administrative login until patching is completed.
On 2025-12-09, Fortinet issued an advisory and released fixes for two critical authentication-bypass vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager when FortiCloud SSO is enabled. The flaws stem from improper cryptographic signature verification in SAML processing and can allow unauthenticated attackers to bypass FortiCloud SSO login with crafted SAML messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourceheise.de
Open sourcearcticwolf.com
Open sourcesecurityaffairs.com
Open sourcearcticwolf.com
Open sourcethreatprotect.qualys.com
Open sourcecve.akaoma.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.