• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-forticloud-sso-login-auth-bypass-flaws/

Fortinet warns of critical FortiCloud SSO login auth bypass flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 9, 2025
·
Updated

Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. Threat actors can exploit the two security flaws tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb) by abusing improper verification of cryptographic signature weaknesses in vulnerable products via a maliciously crafted SAML message. However, as Fortinet explained in an advisory published today, the vulnerable FortiCloud feature is not enabled by default when the device is not FortiCare-registered. "Please note that the FortiCloud SSO login feature is not enabled in default factory settings," Fortinet said. "However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch 'Allow administrative login using FortiCloud SSO' in the registration page, FortiCloud SSO login is enabled upon registration." To protect their systems against attacks exploiting these vulnerabilities, admins are advised to temporarily disable the FortiCloud login feature (if enabled) until they upgrade to a non-vulnerable version. To disable FortiCloud login, navigate to System -> Settings and switch "Allow administrative login using FortiCloud SSO" to Off. Alternatively, you can run the following command from the command-line interface: Today, the company also patched an unverified pa...

Read full article

Affected Software

4 affected components
Fortinet FortiOS
Fortinet FortiWeb
Fortinet FortiProxy
Fortinet FortiSwitchManager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article reports on critical vulnerabilities in FortiCloud SSO authentication across multiple Fortinet products.

2

What security implications are discussed in the article?

The vulnerabilities could allow attackers to bypass authentication, potentially compromising system integrity and user data.

3

What products or software are affected by these vulnerabilities?

The affected products include FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager.

4

What actions has Fortinet taken in response to these vulnerabilities?

Fortinet has released security updates to address the identified critical vulnerabilities.

5

Who is at risk due to these authentication bypass flaws?

Organizations using the affected Fortinet products are at risk of exploitation by threat actors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203