Active Exploitation
#threatreport #MediumCompleteness
FortiGate CVE-2025-59718 Exploitation: Incident Response Findings | 08-04-2026
Source: https://www.rapid7.com/blog/post/ve-fortigate-cve-2025-59718-exploitation-incident-response-ir-findings
Key details below ↓
🧑💻Actors/Campaigns:
Akira_ransomware
💀Threats:
Mimikatz_tool, Credential_dumping_technique, Advanced-port-scanner_tool, Akira_ransomware,
🎯Victims: Fortigate appliances, Firewalls, Internal network hosts, Virtualization platforms, Domain controllers, Backup infrastructure
🏭Industry: Critical_infrastructure
🔓CVEs: CVE-2025-59718 \[[Vulners](https://vulners.com/cve/CVE-2025-59718)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- fortinet fortiproxy (<7.0.22, <7.2.15, <7.4.11, <7.6.4)
- fortinet fortiswitchmanager (<7.0.6, <7.2.7)
- fortinet fortios (<7.0.18, <7.2.12, <7.4.9, <7.6.4)
📚TTPs:
⚔️Tactics: 7
🛠️Technics: 9
🧨IOCs:
- IP: 12
- File: 6
- Domain: 1
💽Software: PsExec, Windows Registry, sysinternals, Velociraptor
#threatreport:
The exploitation of CVE-2025-59718, a vulnerability in FortiGate appliances, has been analyzed following an incident investigated by Rapid7's Incident Response team. This vulnerability allows for a single sign-on (SSO) login bypass, which the attackers exploited in December 2025. After gaining initial access, attackers maintained a low profile, compromising additional firewalls and laterally moving into the internal network. The incident is characterized by systematic credential discovery and the use of legitimate credentials for further access, exemplified by the use of Mimikatz to harvest admin credentials.
The investigation revealed that attackers leveraged common administrative tools and methods for lateral movement, particularly utilizing PsExec and Microsoft Remote Desktop Protocol (RDP). Their primary targets were high-value systems such as virtualization platforms, domain controllers, and backup servers, which could facilitate privilege escalation or unauthorized access to sensitive data. Notably, the attack was initiated from an internal IP address associated with the FortiGate device, despite no legitimate SSL VPN configurations being present in the environment. This discrepancy prompted further scrutiny of the FortiGate device.
Upon examination, investigators identified multiple unauthorized configuration changes, including the activation of the SSL VPN component and the creation of several administrative and local accounts linked to external email domains. This activity was indicative of an ongoing intrusion, with attackers creating persistence mechanisms and modifying firewall rules to secure their access. The first authentication event was traced back to a time when the attackers began establishing their foothold, approximately two weeks prior to detectable malicious activities.
The attack methodology was consistent with multiple MITRE ATT&CK techniques, including exploitation of public-facing applications, creation of accounts for persistence, and the use of valid credentials for lateral movement and initial access. The use of tools like Advanced_Port_Scanner for reconnaissance and the execution of PsExec for lateral movement further illustrate the breadth of techniques employed by the attackers.
To mitigate such vulnerabilities, continuous monitoring of edge devices like firewalls and VPN appliances is essential. Implementing real-time audit trails can help close visibility gaps, providing crucial insights into attempts at configuration changes, connection attempts, and potential exploit signatures. This layered approach can enhance defenses against future exploitative actions.
Post summary
Rapid7’s incident response team confirms real‑world exploitation of CVE‑2025‑59718 in FortiGate appliances via an SSO bypass, with attackers using Mimikatz and PsExec for lateral movement and persistence.