logo

CVE-2025-59718 and CVE-2025-59719: FortiCloud SSO Login Authentication Bypass

ID: a3313b00-5833-5648-b9d4-075ca989c185

STIX ID: report--a3313b00-5833-5648-b9d4-075ca989c185

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2025-12-10

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Fortinet released an advisory on December 9, 2025 describing two critical authentication-bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) that allow unauthenticated bypass of FortiCloud SSO via crafted SAML messages. The advisory lists affected and fixed versions across FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, recommends upgrading to specified fixed versions, and provides a CLI/gui workaround to disable FortiCloud SSO until patched; no in-the-wild exploitation or public PoC is reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.