Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719
ID: ba2e3ffb-5477-5992-aacd-42bff229784b
STIX ID: report--ba2e3ffb-5477-5992-aacd-42bff229784b
Feed Name: Arctic Wolf
Threat Score
Arctic Wolf observed active exploitation beginning 12 December 2025 of two critical Fortinet SSO authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) that allowed unauthenticated admin logins and subsequent configuration downloads; multiple Fortinet product lines are affected and Arctic Wolf provides IOC IPs, example logs, and remediation steps including upgrading to fixed versions, disabling FortiCloud SSO, and resetting credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
