logo

Critical Fortinet Flaws Under Active Attack

ID: e48ae128-b7e3-53bd-89ab-7a56ab5d3fb7

STIX ID: report--e48ae128-b7e3-53bd-89ab-7a56ab5d3fb7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

CISA added a critical Fortinet SAML authentication-bypass vulnerability (CVE-2025-59718) — one of two related high-severity flaws (CVE-2025-59718 and CVE-2025-59719, CVSS 9.1) — to its KEV after vendor and security researchers observed active exploitation where attackers used malicious SSO logins to gain admin access and export device configurations; Fortinet has released patches and recommends disabling FortiCloud SSO or restricting admin access as interim mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.