Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Security Patch Release

FortiGate FortiCloud SSO bypass exploitation

Updated 19.12.2025 17:00
Case score 62
Case score 62 Members 2 Latest activity 19.12.2025 17:00
Active exploitation Patch available CVSS: 9.8 Critical
Members 2 First seen 09.12.2025 20:36 Last seen 16.12.2025 12:58 Updated 19.12.2025 17:00

Overview

**FortiGate** appliances are under active exploitation through **CVE-2025-59718** and **CVE-2025-59719**, which bypass **FortiCloud SSO** on devices that have the feature enabled. Arctic Wolf observed malicious **admin** logins and follow-on configuration exports, showing that the flaws are being used for real access rather than only disclosure testing. Fortinet has patched **FortiOS**, **FortiWeb**, **FortiProxy**, and **FortiSwitchManager** and told administrators to disable **FortiCloud SSO** until systems are upgraded. **CISA** added the issues to its actively exploited catalog with a **December 23** deadline for U.S. government agencies, while available evidence does not quantify how many exposed devices have been secured.

Signals

7 derived
Exploitation
CVSS 9.8 Critical Exploitation Active exploitation
CVEs/products
CVE CVE
Victims/regions
Sector government
Remediation
Urgency High Remediation Patch available

Malware context

1 families

Member happenings

2 related
Exploitation Wave FortiGate FortiCloud SSO authentication bypass active exploitation wave
Updated 16.12.2025 12:58 Lead Contribution 62
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**FortiGate** appliances are in an active exploitation wave after attackers began abusing **CVE-2025-59718** and **CVE-2025-59719** less than a week after disclosure. **Arctic Wolf** observed malicious **SSO logins** on **December 12, 2025**, and the activity quickly escalated to **device configuration exports**. The live abuse matters because successful authentication bypass can expose administrative access and sensitive firewall settings.

Security Patch Release FortiOS/FortiWeb/FortiProxy/FortiSwitchManager FortiCloud SSO auth bypass patch release (CVE-2025-59718, CVE-2025-59719)
Updated 09.12.2025 20:36 Context
CVSS 9.8 Critical Urgency High Patch Patch Available

**Fortinet** patched **FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager** on **December 9** for **CVE-2025-59718** and **CVE-2025-59719**, critical flaws that can bypass **FortiCloud SSO authentication** through a **maliciously crafted SAML message**. The company said the vulnerable **FortiCloud SSO login feature** is not enabled by default on devices that are not **FortiCare-registered**, and administrators were told to **disable FortiCloud SSO login** until they can upgrade to a **non-vulnerable version**. The incident later moved into active exploitation, with attackers abusing the flaws against Fortinet devices that have **FortiCloud SSO** enabled to gain **admin-level access** to the web management interface and download **system configuration files**. **Shadowserver** said it found **over 25,000 Fortinet devices** exposed online with **FortiCloud SSO** enabled, and **CISA** added the issue to its catalog of **actively exploited** vulnerabilities with a **December 23** patch deadline for **U.S. government agencies**.