logo

Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719

ID: 72469957-46a4-5f2d-8296-1d3672124f9b

STIX ID: report--72469957-46a4-5f2d-8296-1d3672124f9b

Feed Name: Arctic Wolf

Threat Score
80/100

Date Published: 2025-12-15

Date Updated: 2026-07-26

Author: Arctic Wolf Labs

...
...

Arctic Wolf observed active exploitation of Fortinet authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) enabling unauthenticated FortiCloud SSO admin logins and subsequent configuration exfiltration from FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager devices; the bulletin includes attacker IP IOCs, example logs, recommended mitigations (reset credentials, restrict management access, disable FortiCloud SSO, and upgrade to fixed versions), and notes that detections are in place.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.