Fortinet warns of critical FortiCloud SSO login auth bypass flaws
ID: bd4553cd-0c75-58f8-9b67-5b08aced9a12
STIX ID: report--bd4553cd-0c75-58f8-9b67-5b08aced9a12
Feed Name: Bleeping Computer
Fortinet released security updates for multiple critical authentication vulnerabilities — primarily CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb) — which permit attackers to bypass FortiCloud SSO by sending maliciously crafted SAML messages that exploit improper cryptographic signature verification; administrators are advised to disable FortiCloud SSO until systems are updated. The advisory also notes additional authentication issues (CVE-2025-59808 and CVE-2025-64471), provides temporary mitigation commands, and highlights Fortinet vulnerabilities' history of being targeted in real-world exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
