Fortinet Fumble: Exploited Vulnerabilities Make CISA’s Naughty List
U.S. CISA has added a Fortinet vulnerability impacting multiple products to its Known Exploited Vulnerabilities catalog. This flaw, tracked as CVE-2025-59718, lets attackers bypass authentication like a sneaky ninja, if FortiCloud SSO is enabled. Fortinet advises disabling this feature until you upgrade to a safer version.

Hot Take:
Oh Fortinet, you cryptic mischief-maker! Just when we thought we could rest easy with our FortiCloud SSO, you go and let cyber villains waltz in like they own the place. Who would’ve thought our biggest threat would be an imposter with a penchant for SAML messages? Time to rethink those administrative toggles, folks!
Key Points:
- Fortinet products hit with critical vulnerabilities, namely CVE-2025-59718 and CVE-2025-59719.
- Vulnerabilities allow unauthenticated attackers to bypass login using crafted SAML messages.
- Fortinet recommends disabling FortiCloud SSO until updates are installed.
- Arctic Wolf observed exploitation beginning just three days post-patch release.
- CISA mandates federal agencies to patch these vulnerabilities by December 23, 2025.
Already a member? Log in here
