CISA has added two critical authentication bypass vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affecting multiple Fortinet products—including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager—to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation. These flaws stem from improper verification of cryptographic signatures in the FortiCloud Single Sign-On (SSO) mechanism, allowing unauthenticated attackers to bypass authentication via specially crafted SAML messages. Fortinet has released advisories and patches, and CISA has set a remediation deadline for federal agencies, urging immediate patching or, if not possible, discontinuation of affected products until mitigations are in place.
The vulnerabilities are not enabled by default but can be activated during FortiCare registration unless administrators disable the relevant SSO toggle. Security researchers have observed exploitation attempts shortly after the patch release, highlighting the urgency for organizations to update their systems. CISA's guidance mandates compliance with BOD 22-01 for federal agencies, and all organizations using affected Fortinet products are strongly advised to apply patches or disable the vulnerable SSO feature to prevent unauthorized access to their networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the KEV listing, CISA directed U.S. federal civilian agencies to remediate CVE-2025-59718 by 2025-12-23 under BOD 22-01 or discontinue use of affected products until fixed. Private-sector organizations were also urged to review exposure and patch immediately.
By 2025-12-17, public proof-of-concept exploits for the Fortinet vulnerabilities had been posted on GitHub and were being validated against vulnerable targets. This added public technical detail to the ongoing exploitation story and increased urgency for defenders to patch or mitigate.
On 2025-12-16, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The agency highlighted the authentication-bypass risk in Fortinet products using FortiCloud SSO and elevated the issue for federal defenders.
By 2025-12-12, attackers were observed actively exploiting the vulnerabilities to bypass FortiCloud SSO authentication with crafted SAML messages and gain administrative access. Reported post-compromise activity included targeting FortiGate admin accounts and exporting device configuration files containing hashed credentials and other sensitive data.
On 2025-12-09, Fortinet released advisories, fixed versions, and mitigation guidance for two critical SAML SSO authentication-bypass flaws affecting multiple products including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Fortinet recommended upgrading promptly and temporarily disabling FortiCloud SSO administrative login or restricting internet-facing management access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcerapid7.com
Open sourcedarkreading.com
Open sourcesecpod.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.