Less than a week after being made public, threat actors have started to take advantage of two recently discovered security vulnerabilities in Fortinet FortiGate devices.
On December 12, 2025, cybersecurity firm Arctic Wolf said that it discovered ongoing intrusions involving fraudulent single sign-on (SSO) logins on FortiGate appliances. Two critical authentication bypasses (CVE-2025-59718 and CVE-2025-59719, CVSS scores: 9.8) are exploited by the assaults. Last week, Fortinet provided patches for the vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager.
If the FortiCloud SSO feature is enabled on impacted devices, these vulnerabilities enable unauthenticated bypass of SSO login authentication via forged SAML messages, according to a recent alert from Arctic Wolf Labs.
Although FortiCloud SSO is deactivated by default, it is automatically enabled during FortiCare registration unless administrators specifically disable read more about Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
