Fortinet disclosed critical authentication bypass vulnerabilities (CVE-2025-59718…
Fortinet disclosed critical authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager affecting FortiCloud SSO login.
Japan's IPA (Information-technology Promotion Agency) published an alert regarding multiple Fortinet products affected by improper digital signature verification vulnerabilities. CVE-2025-59718 and CVE-2025-59719 impact FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Unauthenticated remote attackers can exploit these flaws to bypass authentication when FortiCloud SSO login functionality is enabled.
Fortinet's CVSS assessment indicates that exploit code already exists for these vulnerabilities, heightening the urgency. The FortiCloud SSO login feature is enabled by default when devices are registered via the GUI in FortiCare unless administrators explicitly disable the "Allow administrative login using FortiCloud SSO" option during registration.
Fortinet has released patched versions addressing both vulnerabilities. IPA recommends immediate upgrading to the latest versions following Fortinet's published procedures. As an interim measure, administrators can mitigate risk by disabling the FortiCloud SSO login feature if not required for operations.
Mentioned in this report
Detection guidance
FortiOS Admin Authentication via FortiCloud SSO (Potential Auth Bypass Exploitation)
Detects successful administrative logins using the FortiCloud SSO authentication method, which is the vector abused by CVE-2025-59718/59719 to bypass authentication on FortiOS/FortiWeb/FortiProxy/FortiSwitchManager. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: FortiOS Admin Authentication via FortiCloud SSO
id: f8cd75ca-4b0e-5d1d-b039-c5b73b34f8dc
status: experimental
description: 'Detects successful administrative authentication events using the FortiCloud
SSO method.
Fortinet disclosed CVE-2025-59718 and CVE-2025-59719, improper digital signature
verification flaws allowing unauthenticated remote attackers to bypass authentication
when FortiCloud SSO login is enabled. Any successful admin login via SSO should
be
reviewed for legitimacy, especially from unexpected source addresses or outside
normal
administrative change windows, since exploit code for these CVEs is known to exist.
'
references:
- https://www.ipa.go.jp/
author: Vorant
tags:
- attack.t1078
logsource:
category: authentication
product: fortios
detection:
selection:
action: login
status: success
sso_method:
method|contains: sso
filter:
user|startswith: svc-
condition: selection and sso_method and not filter
falsepositives:
- Legitimate administrators who normally authenticate via configured FortiCloud SSO
integration
- Scheduled service accounts configured to use SSO for automated administrative tasks
level: medium
FortiOS Configuration Change Enabling FortiCloud SSO Admin Login
Detects CLI/configuration changes that enable the FortiCloud SSO administrative login feature, which could indicate an attacker re-enabling or introducing this authentication path as a persistence/backdoor mechanism after gaining access, or enabling it to weaken authentication controls. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: FortiOS FortiCloud SSO Admin Login Feature Enabled via Configuration Change
id: 70fff4aa-600b-5e3d-87f1-1d6b6e8a4452
status: experimental
description: 'Detects configuration events where the FortiCloud SSO administrative
login option is
enabled on FortiOS/FortiProxy/FortiWeb/FortiSwitchManager devices. This setting
is
enabled by default during GUI-based FortiCare registration and is the mechanism
abused
by CVE-2025-59718/CVE-2025-59719 to bypass authentication. Unexpected or unauthorized
enabling of this feature (e.g., outside change-management windows or by non-admin
accounts) should be investigated as it may indicate an attacker weakening authentication
controls to maintain access.
'
references:
- https://www.ipa.go.jp/
author: Vorant
tags:
- attack.t1562.001
logsource:
category: application
product: fortios
service: config
detection:
selection:
cfgpath|contains: system global
cfgattr|contains: admin-sso
enabled_value:
cfgattr|contains: enable
condition: selection and enabled_value
falsepositives:
- Legitimate administrator intentionally enabling FortiCloud SSO during initial device
registration or planned change
- Automated provisioning scripts configuring new devices via FortiCare GUI registration
level: medium
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251217.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free