CVE-2025-59718
published 2025-12-09CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
66.32%
99.2th percentile
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticloud | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 7.0.0 < 7.0.18 | 7.0.18 |
| fortinet | fortios | 7.0.0 – 7.0.17 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.12 | 7.2.12 |
| fortinet | fortios | 7.2.0 – 7.2.11 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.9 | 7.4.9 |
| fortinet | fortios | 7.4.0 – 7.4.8 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortios | 7.6.0 – 7.6.3 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 7.0.0 < 7.0.22 | 7.0.22 |
| fortinet | fortiproxy | 7.0.0 – 7.0.21 | — |
| fortinet | fortiproxy | >= 7.2.0 < 7.2.15 | 7.2.15 |
| fortinet | fortiproxy | 7.2.0 – 7.2.14 | — |
| fortinet | fortiproxy | >= 7.4.0 < 7.4.11 | 7.4.11 |
| fortinet | fortiproxy | 7.4.0 – 7.4.10 | — |
| fortinet | fortiproxy | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortiproxy | 7.6.0 – 7.6.3 | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | >= 7.0.0 < 7.0.6 | 7.0.6 |
| fortinet | fortiswitchmanager | 7.0.0 – 7.0.5 | — |
| fortinet | fortiswitchmanager | >= 7.2.0 < 7.2.7 | 7.2.7 |
| fortinet | fortiswitchmanager | 7.2.0 – 7.2.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect creation of new local admin accounts post-SSO login via logid 0100044547 — watch for cfgpath='system.admin' with unexpected usernames (audit, backup, itadmin, secadmin, support, helpdesk) ↗
- →Alert on FortiGate system config file downloads via GUI (logid 0100032095, action='download') from external or unrecognized IP addresses — this indicates attacker exfiltration of firewall configuration ↗
- →Detect FortiGate SSL VPN settings being enabled or modified via GUI from external IPs — logid 0100044546 with cfgpath='vpn.ssl.settings' is a key post-exploitation persistence indicator ↗
- →Monitor FortiGate logs for creation of SSO forticloud admin accounts — log entries containing 'Object attribute configured(Add system.sso-forticloud-admin @forticloud.com-1)' indicate attacker-created SSO persistence accounts ↗
- →Detect Mimikatz usage on internal hosts following FortiGate compromise — attackers used it to harvest credentials for lateral movement after initial FortiGate access ↗
- →Monitor for PsExec and RDP lateral movement originating from IP addresses in the FortiGate DHCP lease range — unexpected internal IPs in this range authenticating to Windows hosts indicate VPN-based attacker ingress ↗
- →Check for new firewall policy additions (logid 0100044547, cfgpath='firewall.policy', action='Add') shortly after SSO login events as an indicator of attacker-established persistence and access paths ↗
- ·CVE-2025-59718 only affects devices where FortiCloud SSO is enabled; the feature is NOT enabled by default on devices that are not FortiCare-registered, reducing the attack surface ↗
- ·FortiOS 7.4.9 and 7.4.10 do NOT fully remediate CVE-2025-59718; exploitation of patched devices running these versions has been confirmed by Fortinet developers ↗
- ·The vulnerability is applicable to all SAML SSO implementations on affected products, though active exploitation has only been observed via FortiCloud SSO; third-party SAML IdPs and FortiAuthenticator are confirmed NOT impacted ↗
- ·Attacker IOC accounts ([email protected], [email protected]) and associated Cloudflare IPs may change as Fortinet and Cloudflare take action to neutralize them ↗
- ·The attacker established initial access approximately two weeks before any visible malicious activity, meaning detection based solely on post-exploitation events will miss the initial compromise window ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
cisa·2025-12-16·CVSS 9.8
CVE-2025-59718 [CRITICAL] CWE-347 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Vulnerability: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://fortiguard.fortinet.com/psirt/FG-I
Fortinet
Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass
vendor_fortinet·2025-12-09·CVSS 9.8
CVE-2025-59718 [CRITICAL] CWE-347 Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass
FG-IR-25-647: Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated atta
GHSA
GHSA-fjj2-p33c-f8qq: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7
ghsa_unreviewed·2025-12-09
CVE-2025-59718 [CRITICAL] CWE-347 GHSA-fjj2-p33c-f8qq: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
VulnCheck
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
vulncheck·2025·CVSS 9.8
CVE-2025-59718 [CRITICAL] CWE-347 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
Affected: Fortinet Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://arcticwolf.com/resources/blog/
VulnCheck
Fortinet FortiWeb Improper Verification of Cryptographic Signature
vulncheck·2025·CVSS 9.8
CVE-2025-59719 [CRITICAL] Fortinet FortiWeb Improper Verification of Cryptographic Signature
Fortinet FortiWeb Improper Verification of Cryptographic Signature
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Affected: Fortinet FortiWeb
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/; https://www.linkedin.com/posts/drayagha_for-the-latest-fortigate-cves-cve-2025-59718-activity-740721435622628
No detection rules found.
No public exploits indexed.
Qualys
FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
blogs_qualys·2026-07-08
CVE-2026-24858 FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
## Table of Contents
Summary
What Happened
Who should pay attention
WhyIt Matters/ Potential Impact
Recommended Actions
CVEs and Affected Components
Exploitation Status / Threat Activity
Remediation Long Tail: Why Historical Exposure Persists
How Qualys Helps You Discover These Exposures
Use Qualys QueryLanguageto PrioritizeFortiBleedExposure
Detection and Threat Hunting Guidance
Conclusion
Contributor
Frequently Asked Questions (FAQs)
## Key Takeaways
FortiBleed refers to June 2026 public reporting of large-scale credential exposure and abuse targeting internet-reachable FortiGate management and SSL-VPN gateways driven by credential reuse and brute-force, not a single new zero-day.
Risk is highest for internet-exposed FortiGate devices without MFA, with reused or legacy-h
Hackernews
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
blogs_hackernews·2026-06-22·CVSS 9.8
CVE-2026-24858 [CRITICAL] ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
It’s Monday again.
This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.
The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more attacks. Nothing clever. Just sloppy, cheap, and effective.
Here’s the Monday recap. Let’s get into the week’s mess.
## ⚡ Threat of the We
Rapid7
CVE-2026-41940: cPanel & WHM Authentication Bypass
blogs_rapid7·2026-04-29·CVSS 9.3
CVE-2026-41940 [CRITICAL] CVE-2026-41940: cPanel & WHM Authentication Bypass
## Overview
On April 28, 2026, cPanel issued a security update to fix a critical vulnerability affecting the cPanel & WHM and WP Squared products. In the cPanel release notes, the bug was described as "an issue with session loading and saving." CVE-2026-41940 , the identifier subsequently assigned on April 29, 2026, has a CVSS score of 9.8 and allows unauthenticated remote attackers to bypass authentication and gain unauthorized administrative access to the affected systems. First-party cPanel & WHM and WP Squared vendor advisories are available.
cPanel & WHM is web hosting control panel software used to manage websites and servers. WHM provides root-level administration, while cPanel acts as the user-facing interface. Successful exploitation of CVE-2026-41940 grants an attacker control
Rapid7
CVE-2026-33032: Nginx UI Missing MCP Authentication
blogs_rapid7·2026-04-16·CVSS 9.8
CVE-2026-33032 [CRITICAL] CVE-2026-33032: Nginx UI Missing MCP Authentication
## Overview
On March 30, 2026, a security advisory was published for a critical vulnerability affecting Nginx UI . Nginx UI is an open-source web interface to centralize the management of Nginx configurations and SSL certificates. The critical vulnerability, CVE-2026-33032 , was reported in early March by Pluto Security researcher Yotam Perkal and subsequently patched on March 15, 2026. That same day, Pluto Security published a technical blog post with some vulnerability details.
CVE-2026-33032 is a missing authentication bug with a CVSS score of 9.8 ; as a result of missing authentication controls, an unauthenticated attacker can access a Model Context Protocol (MCP) server that can perform privileged operations on managed Nginx web servers. Systems are vulnerable in the default IP allo
Rapid7
FortiGate CVE-2025-59718 Exploitation: Incident Response Findings
blogs_rapid7·2026-04-08·CVSS 9.8
CVE-2025-59718 [CRITICAL] FortiGate CVE-2025-59718 Exploitation: Incident Response Findings
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. In December 2025, Fortinet disclosed this improper verification of cryptographic signature vulnerability that facilitates an SSO login bypass on affected appliances. After the initial exploitation, the attackers maintained a low-profile posture, systematically compromising additional firewalls before moving to internal network hosts. Ultimately, this grace period allowed responders to contain the threat before further impact could occur within the environment. This blog details exploitation insights, attack progression, and practical detection opportunities for defenders handling their own environments.
## Investigative methodology:
Sentinelone
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
blogs_sentinelone·2026-03-10
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
## Overview
Throughout early 2026, SentinelOne’s ® Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment. Each incident was detected and stopped during the lateral movement phase of the attack.
Fortinet has disclosed and issued patches for several high-severity vulnerabilities allowing unauthorized access during the activity period of our investigations. Successful exploitation of these flaws allows an attacker to extract the configuration file from the FortiGate appliance, which frequently contains service account credentials and valuable network topology information for the targeted environment.
We observed a consistent t
Sentinelone
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
blogs_sentinelone·2026-03-10
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
## Overview
Throughout early 2026, SentinelOne’s® Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment. Each incident was detected and stopped during the lateral movement phase of the attack.
Fortinet has disclosed and issued patches for several high-severity vulnerabilities allowing unauthorized access during the activity period of our investigations. Successful exploitation of these flaws allows an attacker to extract the configuration file from the FortiGate appliance, which frequently contains service account credentials and valuable network topology information for the targeted environment.
We observed a consistent th
Bleepingcomputer
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
blogs_bleepingcomputer·2026-01-27·CVSS 9.8
CVE-2026-24858 [CRITICAL] Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
## Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
## Lawrence Abrams
Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions.
The flaw allows attackers to abuse FortiCloud SSO to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices registered to other customers, even when those devices were fully patched against a previously disclosed vulnerability.
The confirmation comes after Fortinet customers reported compromised FortiGate firewalls on January 21, with attackers creating new local administrator accounts
Checkpoint
26th January – Threat Intelligence Report
blogs_checkpoint·2026-01-26
CVE-2025-68143 26th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th January, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
RansomHub ransomware group has claimed responsibility for a cyber-attack on Luxshare, an electronics manufacturer of Apple, Nvidia, LG, Tesla, and others. The threat actors claimed access to 3D CAD models, circuit board designs, and engineering documentation. The company has not yet confirmed the breach.
Check Point Threa
Bleepingcomputer
Fortinet confirms critical FortiCloud auth bypass not fully patched
blogs_bleepingcomputer·2026-01-23·CVSS 9.8
CVE-2025-59718 [CRITICAL] Fortinet confirms critical FortiCloud auth bypass not fully patched
## Fortinet confirms critical FortiCloud auth bypass not fully patched
## Sergiu Gatlan
Days after admins began reporting that their fully patched firewalls are being hacked, Fortinet confirmed it's working to fully address a critical FortiCloud SSO authentication bypass vulnerability that should have already been patched since early December .
This comes after a wave of reports from Fortinet customers about threat actors exploiting a patch bypass for the CVE-2025-59718 vulnerability to compromise fully patched firewalls.
Cybersecurity company Arctic Wolf said on Wednesday that the campaign began on January 15, with attackers creating accounts with VPN access and stealing firewall configurations within seconds, in what appear to be automated attacks. It also added that the attacks are
Bleepingcomputer
Hackers breach Fortinet FortiGate devices, steal firewall configs
blogs_bleepingcomputer·2026-01-22·CVSS 9.8
[CRITICAL] Hackers breach Fortinet FortiGate devices, steal firewall configs
## Hackers breach Fortinet FortiGate devices, steal firewall configs
## Sergiu Gatlan
Fortinet FortiGate devices are being targeted in automated attacks that create rogue accounts and steal firewall configuration data, according to cybersecurity company Arctic Wolf.
The campaign started last week, on January 15, with the attackers exploiting an unknown vulnerability in the devices' single sign-on (SSO) feature to create accounts with VPN access and exporting firewall configurations within seconds, indicating automated activity.
Arctic Wolf, which reported these incidents on Wednesday , says the attacks are very similar to incidents it documented in December following the disclosure of a critical authentication bypass vulnerability (CVE-2025-59718) in Fortinet products.
That flaw allow
Fortinet
Analysis of Single Sign-On Abuse on FortiOS | Fortinet Blog
blogs_fortinet·2026-01-22·CVSS 9.8
[CRITICAL] Analysis of Single Sign-On Abuse on FortiOS | Fortinet Blog
PSIRT BLOGS
Analysis of Single Sign-On Abuse on FortiOS
By Carl Windsor | January 22, 2026
Incident Updates:
January 23: Fortinet disabled FortiCloud accounts that were being abused as part of the attack.
January 26: Fortinet disabled FortiCloud SSO to prevent abuse.
January 27: Fortinet issued Public Advisory
January 27: FortiCloud SSO access restored; however, it will no longer support access from vulnerable devices. Please follow the upgrade advice specified in the Public Advisory.
January 28: Confirmed that third-party SAML IdPs and FortiAuthenticator are not impacted by this issue. Blog text below has been amended accordingly.
January 30: Fortinet updated the Public Advisory with the last of the release updates.
In December 2025, Fortinet issued an advisory related to two For
Wiz
Crying Out Cloud Monthly Newsletter - January 2026 | Wiz
blogs_wiz·2026-01-22·CVSS 8.7
CVE-2025-55182 [HIGH] Crying Out Cloud Monthly Newsletter - January 2026 | Wiz
Welcome back! In this edition, we bring you the latest in cloud security: noteworthy incidents, exclusive data, and crucial vulnerabilities. Let’s jump in.
## 🔍 Highlights
React2Shell: Critical RCE Vulnerability in React and Next.js
React2Shell (CVE-2025-55182) is a critical, unauthenticated remote code execution vulnerability rooted in insecure deserialization within the React Server Components (RSC) “Flight” protocol, impacting React 19 and RSC-enabled frameworks, most notably Next.js. The flaw affects default configurations, meaning standard production deployments can be exploited with a single crafted HTTP request and no developer misconfiguration, with exploitation demonstrating near-100% reliability.
Since early December 2025, exploitation has been observed in the wild by multipl
Bleepingcomputer
Fortinet admins report patched FortiGate firewalls getting hacked
blogs_bleepingcomputer·2026-01-21·CVSS 9.8
CVE-2025-59718 [CRITICAL] Fortinet admins report patched FortiGate firewalls getting hacked
## Fortinet admins report patched FortiGate firewalls getting hacked
## Sergiu Gatlan
Fortinet customers are seeing attackers exploiting a patch bypass for a previously fixed critical FortiGate authentication vulnerability (CVE-2025-59718) to hack patched firewalls.
One of the affected admins said that Fortinet has allegedly confirmed that the latest FortiOS version (7.4.10) didn't fully address this authentication bypass vulnerability, which should've been patched in early December with the release of FortiOS 7.4.9.
Fortinet is also reportedly planning to release FortiOS 7.4.11, 7.6.6, and 8.0.0 over the coming days to fully patch the security flaw.
"We just had a malicious SSO login on one of our FortiGate's running on 7.4.9 (FGT60F). We have a SIEM that caught the local admin accou
Bleepingcomputer
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
blogs_bleepingcomputer·2026-01-02·CVSS 9.8
CVE-2020-12812 [CRITICAL] Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
## Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
## Sergiu Gatlan
Over 10,000 Fortinet firewalls are still exposed online and vulnerable to ongoing attacks exploiting a five-year-old critical two-factor authentication (2FA) bypass vulnerability.
Fortinet released FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020 to address this flaw (tracked as CVE-2020-12812 ) and advised admins who couldn't immediately patch to turn off username-case-sensitivity to block 2FA bypass attempts targeting their devices.
This improper authentication security flaw (rated 9.8/10 in severity) was found in FortiGate SSL VPN and allows attackers to log in to unpatched firewalls without being prompted for the second factor of authentication (FortiToken) when the username's case is cha
Checkpoint
22nd December – Threat Intelligence Report
blogs_checkpoint·2025-12-22
CVE-2025-37164 22nd December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
An adult content platform PornHub has disclosed a data breach linked to analytics provider Mixpanel. The breach exposed more than 200 million records related to Premium users, including email addresses, search, watch, and download histories, locations, and associated video details collected prior to 2021. Pornhub stated
Bleepingcomputer
Over 25,000 FortiCloud SSO devices exposed to remote attacks
blogs_bleepingcomputer·2025-12-19·CVSS 9.8
CVE-2025-59718 [CRITICAL] Over 25,000 FortiCloud SSO devices exposed to remote attacks
## Over 25,000 FortiCloud SSO devices exposed to remote attacks
## Sergiu Gatlan
Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability.
Fortinet noted on December 9th, when it patched the security flaw tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb), that the vulnerable FortiCloud SSO login feature is not enabled until admins register the device with the company's FortiCare support service.
As cybersecurity company Arctic Wolf reported on Monday , the vulnerability is now actively exploited to compromise admin accounts via malicious single sign-on (SSO) logins.
Threat actors are abusing it i
Talos
Adios 2025, you won’t be missed
blogs_talos·2025-12-18
Adios 2025, you won’t be missed
Welcome to this week’s edition of the Threat Source newsletter.
For us in America, we’re in the holiday doldrums and things slow and/or shut down until the new year. At Cisco, we shut down the last week of the year to reset and recharge, and I’ve grown to be quite fond of it. I’ve worked plenty of gigs where there were no holiday breaks, and now that I’m living that dream, I gotta tell ya, it’s a damn civilized way to live if you can get it.
It’s only natural for us to think on 2025 — what happened to us, what made the news, and with some trepidation (and maybe some hope) what lies in store for 2026.
I thought I’d summarize the notable things that come to mind for me:
1. Uncovering Qilin attack methods exposed through multiple cases
Why this one? Quilin is one of the more aggressive ca
Talos
Adios 2025, you won’t be missed
blogs_talos·2025-12-18
Adios 2025, you won’t be missed
## Adios 2025, you won’t be missed
Welcome to this week’s edition of the Threat Source newsletter.
For us in America, we’re in the holiday doldrums and things slow and/or shut down until the new year. At Cisco, we shut down the last week of the year to reset and recharge, and I’ve grown to be quite fond of it. I’ve worked plenty of gigs where there were no holiday breaks, and now that I’m living that dream, I gotta tell ya, it’s a damn civilized way to live if you can get it.
It’s only natural for us to think on 2025 — what happened to us, what made the news, and with some trepidation (and maybe some hope) what lies in store for 2026.
I thought I’d summarize the notable things that come to mind for me:
Uncovering Qilin attack methods exposed through multiple cases Why this one? Quilin
Bleepingcomputer
Hackers exploit newly patched Fortinet auth bypass flaws
blogs_bleepingcomputer·2025-12-16·CVSS 9.8
CVE-2025-59718 [CRITICAL] Hackers exploit newly patched Fortinet auth bypass flaws
## Hackers exploit newly patched Fortinet auth bypass flaws
## Bill Toulas
Hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files.
The two vulnerabilities are tracked as CVE-2025-59718 and CVE-2025-59719, and Fortinet warned in an advisory on December 9 about the potential for exploitation.
CVE-2025-59718 is a FortiCloud SSO authentication bypass affecting FortiOS, FortiProxy, and FortiSwitchManager. It is caused by improper verification of cryptographic signatures in SAML messages, allowing an attacker to log in without valid authentication by submitting a maliciously crafted SAML assertion.
CVE-2025-59719 is a FortiCloud SSO authentication bypass affecting FortiWe
Bleepingcomputer
Fortinet warns of critical FortiCloud SSO login auth bypass flaws
blogs_bleepingcomputer·2025-12-09·CVSS 9.8
CVE-2025-59718 [CRITICAL] Fortinet warns of critical FortiCloud SSO login auth bypass flaws
## Fortinet warns of critical FortiCloud SSO login auth bypass flaws
## Sergiu Gatlan
Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication.
Threat actors can exploit the two security flaws tracked as CVE-2025-59718 (FortiOS, FortiProxy, FortiSwitchManager) and CVE-2025-59719 (FortiWeb) by abusing improper verification of cryptographic signature weaknesses in vulnerable products via a maliciously crafted SAML message.
However, as Fortinet explained in an advisory published today, the vulnerable FortiCloud feature is not enabled by default when the device is not FortiCare-registered.
"Please note that the FortiCloud SSO login feature is no
Wiz
CVE-2025-59718 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.8
CVE-2025-59718 [MEDIUM] CVE-2025-59718 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-59718 :
FortiOS vulnerability analysis and mitigation
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Source : NVD
## 9.8
Score
Published December 9, 2025
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·CVSS 7.8
CVE-2025-55182 [HIGH] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
# December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
- React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
- China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
- Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-conce
Greynoiseio
NoiseLetter December 2025
blogs_greynoiseio·CVSS 10.0
[CRITICAL] NoiseLetter December 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://fortiguard.fortinet.com/psirt/FG-IR-25-647https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/https://cert-portal.siemens.com/productcert/html/ssa-864900.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718
2025-12-09
Published
2025-12-16
Added to CISA KEV
Exploited in the wild