logo

Fortinet FortiCloud SSO Authentication Bypass Vulnerabilities Actively Exploited (CVE-2025-59718, CVE-2025-59719)

ID: 3aed5f74-deee-5e93-b29b-16f1e0397bc7

STIX ID: report--3aed5f74-deee-5e93-b29b-16f1e0397bc7

Feed Name: Kudelski Security

Threat Score
80/100

Date Published: 2025-12-18

Date Updated: 2026-07-22

...
...

Active exploitation was observed beginning December 12, 2025, of two critical Fortinet SSO authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) that permit unauthenticated attackers to gain administrative access and export device configurations on FortiCloud SSO-enabled FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb devices; Fortinet released patches on December 9, 2025, and the advisory provides IOCs, example logs, recommended fixed versions, and temporary mitigations such as disabling FortiCloud SSO.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.