• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-newly-patched-fortinet-auth-bypass-flaws/

Hackers exploit newly patched Fortinet auth bypass flaws

BleepingComputer
·
Bill Toulas
·
Published Dec 16, 2025
·
Updated

Hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files. The two vulnerabilities are tracked as CVE-2025-59718 and CVE-2025-59719, and Fortinet warned in an advisory on December 9 about the potential for exploitation. CVE-2025-59718 is a FortiCloud SSO authentication bypass affecting FortiOS, FortiProxy, and FortiSwitchManager. It is caused by improper verification of cryptographic signatures in SAML messages, allowing an attacker to log in without valid authentication by submitting a maliciously crafted SAML assertion. CVE-2025-59719 is a FortiCloud SSO authentication bypass affecting FortiWeb. It arises from a similar issue with the cryptographic signature validation of SAML messages, enabling unauthenticated administrative access via forged SSO. Both issues are only exploitable if FortiCloud SSO is enabled, which is not the default setting. However, unless the feature is explicitly disabled, it is activated automatically when registering devices through the FortiCare user interface. Researchers at cybersecurity company Arctic Wolf observed attacks exploiting the two security vulnerabilities starting on December 12. They note that the intrusions originated from several IP addresses linked to The Constant Company, BL Networks, and Kaopu Cloud HK. Based on Arctic Wolf observations, the attackers targeted admin accounts with malicious single sign-on logins (...

Read full article

Affected Software

4 affected components
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiSwitchManager
Fortinet FortiWeb
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being exploited in Fortinet products?

Hackers are exploiting two critical-severity vulnerabilities tracked as CVE-2025-59718 and CVE-2025-59719.

2

What types of products are affected by these security vulnerabilities?

The affected products include FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb.

3

What is the potential impact of these vulnerabilities?

The vulnerabilities allow unauthorized access to admin accounts and the theft of system configuration files.

4

How are attackers taking advantage of these vulnerabilities?

Attackers are exploiting authentication bypass flaws to gain unauthorized access.

5

What should Fortinet users do in response to these vulnerabilities?

Fortinet users are advised to apply the latest patches released by Fortinet to mitigate these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203