CRITICAL ALERT: Critical vulnerabilities in multiple Fortinet products - FortiCloud SSO Login Authentication Bypass
ID: 79d54c16-ee09-5856-84fe-37075296c645
STIX ID: report--79d54c16-ee09-5856-84fe-37075296c645
Feed Name: ASD's ACSC - Alerts RSS
Date Published: 2025-12-10
Date Updated: 2026-07-24
Author: Australian Cyber Security Centre (ACSC)
Fortinet disclosed two critical SAML signature verification vulnerabilities (CVE-2025-59718, CVE-2025-59719) impacting multiple versions of FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb; these flaws can allow an unauthenticated attacker to bypass FortiCloud SSO via a crafted SAML response. The advisory recommends organisations promptly apply patches, consider disabling FortiCloud login until patched, and investigate for signs of unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
