logo

CISA Adds Fortinet Vulnerability to KEV Catalog After Active Exploitation

ID: e364bfc1-1d61-52ea-a757-f74bf369c555

STIX ID: report--e364bfc1-1d61-52ea-a757-f74bf369c555

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog on December 16, 2025, setting a December 23, 2025 remediation deadline after reports of active exploitation; the flaw (CWE-347) affects Fortinet products (FortiOS, FortiSwitchMaster, FortiProxy, FortiWeb) and permits unauthenticated SAML-based authentication bypass to FortiCloud SSO, and administrators are urged to apply vendor patches immediately or discontinue affected products until mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.