Fortinet Fumble: Exploited Vulnerabilities Make CISA’s Naughty List

U.S. CISA has added a Fortinet vulnerability impacting multiple products to its Known Exploited Vulnerabilities catalog. This flaw, tracked as CVE-2025-59718, lets attackers bypass authentication like a sneaky ninja, if FortiCloud SSO is enabled. Fortinet advises disabling this feature until you upgrade to a safer version.

Pro Dashboard

Hot Take:

Oh Fortinet, you cryptic mischief-maker! Just when we thought we could rest easy with our FortiCloud SSO, you go and let cyber villains waltz in like they own the place. Who would’ve thought our biggest threat would be an imposter with a penchant for SAML messages? Time to rethink those administrative toggles, folks!

Key Points:

  • Fortinet products hit with critical vulnerabilities, namely CVE-2025-59718 and CVE-2025-59719.
  • Vulnerabilities allow unauthenticated attackers to bypass login using crafted SAML messages.
  • Fortinet recommends disabling FortiCloud SSO until updates are installed.
  • Arctic Wolf observed exploitation beginning just three days post-patch release.
  • CISA mandates federal agencies to patch these vulnerabilities by December 23, 2025.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?