FortiGate FortiCloud SSO bypass exploitation
Case score 62
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 62
- Main story score
- 62
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 1
- Exploitation Wave Active exploitation of FortiGate appliances with confirmed malicious SSO logins and post-login configuration export. main
- Security Patch Release Fortinet's December fixes and mitigation guidance for the same CVEs support the response narrative. context
Overview
Latest development Open development history Malicious SSO logins and configuration exports on FortiGate appliances Malicious SSO logins against FortiGate appliances on December 12, 2025 used IP addresses associated with The Constant Company llc, Bl Networks, and Kaopu Cloud Hk Limited to target the admin account, and follow-on activity exported device configurations through the GUI, consistent with active exploitation of CVE-2025-59718 and CVE-2025-59719 on devices with FortiCloud SSO enabled.
-
Active exploitation of FortiCloud SSO bypass targets Fortinet devices
Attackers are actively exploiting CVE-2025-59718 and CVE-2025-59719 against Fortinet devices with FortiCloud SSO enabled, using maliciously crafted SAML messages to gain admin-level access to the web management interface and download system configuration files. Shadowserver counted more than 25,000 exposed Fortinet IPs with FortiCloud SSO fingerprints, and CISA added the flaw to its catalog of actively exploited vulnerabilities with a December 23 patch deadline for U.S. government agencies.
-
FortiGate authentication bypass and mitigation guidance disclosed
Arctic Wolf warned that FortiGate devices with FortiCloud SSO enabled can be bypassed through crafted SAML messages, identified CVE-2025-59718 and CVE-2025-59719 as critical authentication bypasses with CVSS scores of 9.8, and advised organizations to apply Fortinet's patches for FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, disable FortiCloud SSO until updated, and restrict management interface access to trusted internal users.
-
Fortinet releases fixes for FortiCloud SSO bypass flaws
Fortinet released security updates for FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager to fix CVE-2025-59718 and CVE-2025-59719, critical vulnerabilities that could let attackers bypass FortiCloud SSO authentication by sending a maliciously crafted SAML message. Fortinet said the FortiCloud SSO login feature is not enabled in default factory settings on non-FortiCare-registered devices, and advised administrators to disable FortiCloud SSO login until they can upgrade to a non-vulnerable version.