Two critical authentication bypass vulnerabilities, CVE-2025-59718 and CVE-2025-59719, have been identified in Fortinet products utilizing the FortiCloud SSO login feature. These flaws stem from improper verification of cryptographic signatures (CWE-347), allowing unauthenticated attackers to bypass SSO authentication and potentially gain administrative access. The vulnerabilities affect multiple Fortinet product lines, including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, when FortiCloud SSO is enabled. Fortinet has clarified that FortiCloud SSO is disabled by default, but it becomes enabled if devices are registered via FortiCare through the GUI unless the relevant setting is manually disabled.
Following public disclosure of these vulnerabilities, Arctic Wolf observed active exploitation attempts targeting FortiGate appliances. Malicious SSO logins were traced to several hosting providers, with attackers typically attempting to access the admin account. Indicators of compromise (IOCs) include specific IP addresses from The Constant Company LLC, Bl Networks, and Kaopu Cloud HK Limited. Organizations using affected Fortinet products are urged to review their SSO configurations, apply vendor patches, and monitor for suspicious login activity, especially from the identified IOCs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-08, Rapid7 published incident-response findings from a FortiGate intrusion tied to CVE-2025-59718, describing how attackers enabled SSL VPN, created admin accounts, altered firewall policies, downloaded configs, and pivoted into the internal network for discovery, credential theft, and lateral movement. Rapid7 also released detections for suspicious FortiGate admin SSO logins, configuration downloads, and anomalous external-IP authentication activity.
By 2025-12-19, reporting based on Shadowserver Foundation scanning said more than 25,000 Fortinet devices with FortiCloud SSO enabled were exposed online. The finding highlighted the large internet-facing attack surface for the actively exploited vulnerabilities, though not all exposed devices were necessarily unpatched or vulnerable.
By 2025-12-16, the U.S. Cybersecurity and Infrastructure Security Agency had added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, requiring U.S. federal agencies to remediate it. Multiple reports noted a remediation deadline of 2025-12-23 for federal civilian agencies.
On 2025-12-15, Arctic Wolf publicly reported the observed intrusions, describing malicious admin logins, configuration downloads, and source IP infrastructure linked to the activity. It advised organizations to patch, disable FortiCloud SSO if needed, restrict management access, and reset credentials if compromise is suspected.
On 2025-12-15, the Canadian Centre for Cyber Security warned that CVE-2025-59718 and CVE-2025-59719 pose a critical risk to affected Fortinet products and urged organizations to upgrade or disable FortiCloud login as a temporary mitigation. The alert also recommended broader defensive measures such as patching, segmentation, and isolating web-facing applications.
Beginning on 2025-12-12, Arctic Wolf observed malicious SSO-based logins to FortiGate devices exploiting the newly disclosed flaws. The activity typically targeted built-in admin accounts and was followed by configuration exports, creating risk of credential exposure from exfiltrated files.
On 2025-12-09, Fortinet publicly disclosed CVE-2025-59718 and CVE-2025-59719, two critical authentication bypass vulnerabilities affecting products that use FortiCloud SSO login, and released fixed versions. The flaws stem from improper verification of cryptographic signatures in SAML messages and can allow unauthenticated administrative access when FortiCloud SSO is enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
rapid7.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcearcticwolf.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.