logo

Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719

ID: ba2e3ffb-5477-5992-aacd-42bff229784b

STIX ID: report--ba2e3ffb-5477-5992-aacd-42bff229784b

Feed Name: Arctic Wolf

Threat Score
80/100

Date Published: 2025-12-16

Date Updated: 2026-07-26

Author: Arctic Wolf Labs

...
...

Arctic Wolf observed active exploitation beginning 12 December 2025 of two critical Fortinet SSO authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) that allowed unauthenticated admin logins and subsequent configuration downloads; multiple Fortinet product lines are affected and Arctic Wolf provides IOC IPs, example logs, and remediation steps including upgrading to fixed versions, disabling FortiCloud SSO, and resetting credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.