Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Security Patch Release

FortiGate FortiCloud SSO bypass exploitation

Updated 19.12.2025 17:00
Case score 62
Members 2 First seen 09.12.2025 20:36 Latest activity 19.12.2025 17:00

Overview

**FortiGate** appliances are under active exploitation through **CVE-2025-59718** and **CVE-2025-59719**, which bypass **FortiCloud SSO** on devices that have the feature enabled. Arctic Wolf observed malicious **admin** logins and follow-on configuration exports, showing that the flaws are being used for real access rather than only disclosure testing. Fortinet has patched **FortiOS**, **FortiWeb**, **FortiProxy**, and **FortiSwitchManager** and told administrators to disable **FortiCloud SSO** until systems are upgraded. **CISA** added the issues to its actively exploited catalog with a **December 23** deadline for U.S. government agencies, while available evidence does not quantify how many exposed devices have been secured.
Latest development Open development history 3 earlier developments Malicious SSO logins and configuration exports on FortiGate appliances Malicious SSO logins against FortiGate appliances on December 12, 2025 used IP addresses associated with The Constant Company llc, Bl Networks, and Kaopu Cloud Hk Limited to target the admin account, and follow-on activity exported device configurations through the GUI, consistent with active exploitation of CVE-2025-59718 and CVE-2025-59719 on devices with FortiCloud SSO enabled.
  1. Earlier development

    Active exploitation of FortiCloud SSO bypass targets Fortinet devices

    Attackers are actively exploiting CVE-2025-59718 and CVE-2025-59719 against Fortinet devices with FortiCloud SSO enabled, using maliciously crafted SAML messages to gain admin-level access to the web management interface and download system configuration files. Shadowserver counted more than 25,000 exposed Fortinet IPs with FortiCloud SSO fingerprints, and CISA added the flaw to its catalog of actively exploited vulnerabilities with a December 23 patch deadline for U.S. government agencies.

  2. Earlier development

    FortiGate authentication bypass and mitigation guidance disclosed

    Arctic Wolf warned that FortiGate devices with FortiCloud SSO enabled can be bypassed through crafted SAML messages, identified CVE-2025-59718 and CVE-2025-59719 as critical authentication bypasses with CVSS scores of 9.8, and advised organizations to apply Fortinet's patches for FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, disable FortiCloud SSO until updated, and restrict management interface access to trusted internal users.

  3. Earlier development

    Fortinet releases fixes for FortiCloud SSO bypass flaws

    Fortinet released security updates for FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager to fix CVE-2025-59718 and CVE-2025-59719, critical vulnerabilities that could let attackers bypass FortiCloud SSO authentication by sending a maliciously crafted SAML message. Fortinet said the FortiCloud SSO login feature is not enabled in default factory settings on non-FortiCare-registered devices, and advised administrators to disable FortiCloud SSO login until they can upgrade to a non-vulnerable version.

Signals

Exploitation
CVEs/products
Geographic context
Remediation

Threat actor context

1 listed

Malware context

1 families

Member happenings

Exploitation Wave FortiGate FortiCloud SSO authentication bypass active exploitation wave
Updated 16.12.2025 12:58 Lead Contribution 62
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**FortiGate** appliances are in an active exploitation wave after attackers began abusing **CVE-2025-59718** and **CVE-2025-59719** less than a week after disclosure. **Arctic Wolf** observed malicious **SSO logins** on **December 12, 2025**, and the activity quickly escalated to **device configuration exports**. The live abuse matters because successful authentication bypass can expose administrative access and sensitive firewall settings.

Security Patch Release FortiOS/FortiWeb/FortiProxy/FortiSwitchManager FortiCloud SSO auth bypass patch release (CVE-2025-59718, CVE-2025-59719)
Updated 09.12.2025 20:36 Context
CVSS 9.8 Critical Urgency High Patch Patch Available

**Fortinet** patched **FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager** on **December 9** for **CVE-2025-59718** and **CVE-2025-59719**, critical flaws that can bypass **FortiCloud SSO authentication** through a **maliciously crafted SAML message**. The company said the vulnerable **FortiCloud SSO login feature** is not enabled by default on devices that are not **FortiCare-registered**, and administrators were told to **disable FortiCloud SSO login** until they can upgrade to a **non-vulnerable version**. The incident later moved into active exploitation, with attackers abusing the flaws against Fortinet devices that have **FortiCloud SSO** enabled to gain **admin-level access** to the web management interface and download **system configuration files**. **Shadowserver** said it found **over 25,000 Fortinet devices** exposed online with **FortiCloud SSO** enabled, and **CISA** added the issue to its catalog of **actively exploited** vulnerabilities with a **December 23** patch deadline for **U.S. government agencies**.