VORANT. Threat Intelligence Sign in Get the full feed

Fortinet auth bypass flaws exploited via SSO

critical vulnerability

Fortinet disclosed critical signature-verification flaws in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager allowing unauthenticated remote attackers to bypass authentication via FortiCloud SSO.

Japan's IPA published an advisory on two digital-signature-verification vulnerabilities in multiple Fortinet products: FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. The flaws, tracked as CVE-2025-59718 and CVE-2025-59719, enable unauthenticated remote attackers to bypass authentication when FortiCloud SSO login functionality is enabled. Fortinet's CVSS assessment indicates exploit code already exists for these vulnerabilities.

The vulnerabilities affect devices where FortiCloud SSO login is active, which can occur when administrators register the device with FortiCare via the GUI without explicitly disabling the "Allow administrative login using FortiCloud SSO" option. IPA warns that exploitation risk is escalating and urges immediate patching.

Fortinet has released patches for affected versions and recommends upgrading immediately. As a workaround, administrators can mitigate the risk by disabling FortiCloud SSO login functionality until patches are applied.

Mentioned in this report

Vulnerabilities CVE-2025-59718KEVCVE-2025-59719

Detection guidance

FortiGate Administrative Login via FortiCloud SSO

ATT&CK T1078

Detects successful FortiGate/FortiProxy/FortiWeb administrative logins authenticated via FortiCloud SSO, a login path that unauthenticated attackers can abuse to bypass authentication when CVE-2025-59718/CVE-2025-59719 are present and SSO login is enabled. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: FortiGate Administrative Login via FortiCloud SSO
id: d8506b15-f3d0-54eb-8629-9acfa7da31da
status: experimental
description: 'Detects successful administrative authentication events on Fortinet
  devices

  (FortiOS, FortiProxy, FortiWeb, FortiSwitchManager) where the login method

  is FortiCloud SSO. This login path is affected by CVE-2025-59718 and

  CVE-2025-59719, which allow unauthenticated remote attackers to bypass

  authentication when FortiCloud SSO admin login is enabled. Any SSO-based

  admin login should be reviewed, especially from unexpected source IPs or

  for accounts that do not normally use SSO.

  '
references:
- https://www.fortiguard.com/psirt
author: Vorant
tags:
- attack.t1078
- attack.defense-evasion
- attack.initial-access
logsource:
  category: firewall
  product: fortios
detection:
  selection:
    logdesc|contains:
    - Admin login successful
    - SSO admin login
    method|contains: sso
  condition: selection
falsepositives:
- Legitimate administrators intentionally using FortiCloud SSO for device management
  where this is an approved and expected authentication path
- Scheduled automation or monitoring integrations that authenticate via FortiCloud
  SSO
level: medium

FortiOS Configuration Change Enabling FortiCloud SSO Admin Login

ATT&CK T1078

Detects configuration changes that enable the 'Allow administrative login using FortiCloud SSO' option, which expands the attack surface for CVE-2025-59718/CVE-2025-59719 authentication bypass. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: FortiOS Configuration Change Enabling FortiCloud SSO Admin Login
id: c14c4581-586f-51c5-9c91-416da2604e6f
status: experimental
description: 'Detects configuration events indicating that FortiCloud SSO administrative

  login was enabled on a Fortinet device (FortiOS, FortiProxy, FortiWeb,

  FortiSwitchManager). Enabling this feature exposes the device to

  CVE-2025-59718 and CVE-2025-59719, which allow unauthenticated remote

  attackers to bypass authentication. Config changes turning this setting on

  should be reviewed, particularly if performed outside of a planned

  maintenance window or by an unexpected admin account.

  '
references:
- https://www.fortiguard.com/psirt
author: Vorant
tags:
- attack.t1078
- attack.defense-evasion
logsource:
  category: firewall
  product: fortios
detection:
  selection:
    logdesc|contains: Configuration changed
    cfgpath|contains: system.global
    cfgattr|contains: admin-sso
    action|contains: enable
  condition: selection
falsepositives:
- Intentional administrative enablement of FortiCloud SSO login during initial device
  setup or planned configuration change
level: low

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251217.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free