Fortinet auth-bypass flaws have public exploit code
Two Fortinet vulnerabilities allow unauthenticated remote attackers to bypass authentication via improper digital signature verification, and exploit code reportedly already exists.
Japan's IPA issued an alert on two Fortinet vulnerabilities, CVE-2025-59718 and CVE-2025-59719, affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Both stem from improper verification of digital signatures and could allow an unauthenticated remote attacker to bypass authentication. The flaws are specifically tied to environments where FortiCloud SSO login is enabled — a setting that, per Fortinet, can be left active by default when device registration is completed via the GUI without explicitly disabling the 'Allow administrative login using FortiCloud SSO' option.
According to the vendor's own CVSS assessment, exploit code for these vulnerabilities already exists, raising concern about near-term exploitation despite no confirmed in-the-wild attacks being reported at time of publication. IPA is urging organizations to apply the vendor-provided patches and follow the published upgrade procedures, or apply available workarounds where immediate patching is not feasible, given the breadth of deployment of these Fortinet products in enterprise network perimeters.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251217.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free