VORANT. Threat Intelligence Sign in Get the full feed

Fortinet disclosed critical authentication bypass vulnerabilities (CVE-2025-59718…

critical vulnerability

Fortinet disclosed critical authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager affecting FortiCloud SSO login.

Japan's IPA (Information-technology Promotion Agency) published an alert regarding multiple Fortinet products affected by improper digital signature verification vulnerabilities. CVE-2025-59718 and CVE-2025-59719 impact FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Unauthenticated remote attackers can exploit these flaws to bypass authentication when FortiCloud SSO login functionality is enabled.

Fortinet's CVSS assessment indicates that exploit code already exists for these vulnerabilities, heightening the urgency. The FortiCloud SSO login feature is enabled by default when devices are registered via the GUI in FortiCare unless administrators explicitly disable the "Allow administrative login using FortiCloud SSO" option during registration.

Fortinet has released patched versions addressing both vulnerabilities. IPA recommends immediate upgrading to the latest versions following Fortinet's published procedures. As an interim measure, administrators can mitigate risk by disabling the FortiCloud SSO login feature if not required for operations.

Mentioned in this report

Vulnerabilities CVE-2025-59718KEVCVE-2025-59719

Detection guidance

FortiOS Admin Authentication via FortiCloud SSO (Potential Auth Bypass Exploitation)

ATT&CK T1078

Detects successful administrative logins using the FortiCloud SSO authentication method, which is the vector abused by CVE-2025-59718/59719 to bypass authentication on FortiOS/FortiWeb/FortiProxy/FortiSwitchManager. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: FortiOS Admin Authentication via FortiCloud SSO
id: f8cd75ca-4b0e-5d1d-b039-c5b73b34f8dc
status: experimental
description: 'Detects successful administrative authentication events using the FortiCloud
  SSO method.

  Fortinet disclosed CVE-2025-59718 and CVE-2025-59719, improper digital signature

  verification flaws allowing unauthenticated remote attackers to bypass authentication

  when FortiCloud SSO login is enabled. Any successful admin login via SSO should
  be

  reviewed for legitimacy, especially from unexpected source addresses or outside
  normal

  administrative change windows, since exploit code for these CVEs is known to exist.

  '
references:
- https://www.ipa.go.jp/
author: Vorant
tags:
- attack.t1078
logsource:
  category: authentication
  product: fortios
detection:
  selection:
    action: login
    status: success
  sso_method:
    method|contains: sso
  filter:
    user|startswith: svc-
  condition: selection and sso_method and not filter
falsepositives:
- Legitimate administrators who normally authenticate via configured FortiCloud SSO
  integration
- Scheduled service accounts configured to use SSO for automated administrative tasks
level: medium

FortiOS Configuration Change Enabling FortiCloud SSO Admin Login

ATT&CK T1562.001

Detects CLI/configuration changes that enable the FortiCloud SSO administrative login feature, which could indicate an attacker re-enabling or introducing this authentication path as a persistence/backdoor mechanism after gaining access, or enabling it to weaken authentication controls. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: FortiOS FortiCloud SSO Admin Login Feature Enabled via Configuration Change
id: 70fff4aa-600b-5e3d-87f1-1d6b6e8a4452
status: experimental
description: 'Detects configuration events where the FortiCloud SSO administrative
  login option is

  enabled on FortiOS/FortiProxy/FortiWeb/FortiSwitchManager devices. This setting
  is

  enabled by default during GUI-based FortiCare registration and is the mechanism
  abused

  by CVE-2025-59718/CVE-2025-59719 to bypass authentication. Unexpected or unauthorized

  enabling of this feature (e.g., outside change-management windows or by non-admin

  accounts) should be investigated as it may indicate an attacker weakening authentication

  controls to maintain access.

  '
references:
- https://www.ipa.go.jp/
author: Vorant
tags:
- attack.t1562.001
logsource:
  category: application
  product: fortios
  service: config
detection:
  selection:
    cfgpath|contains: system global
    cfgattr|contains: admin-sso
  enabled_value:
    cfgattr|contains: enable
  condition: selection and enabled_value
falsepositives:
- Legitimate administrator intentionally enabling FortiCloud SSO during initial device
  registration or planned change
- Automated provisioning scripts configuring new devices via FortiCare GUI registration
level: medium

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251217.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free