CVE-2025-59718Active Exploitation(fortinet / fortios)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-347

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy
  • fortiswitchmanager
  • ruggedcom_ape1808

Threat summary

  • Active exploitation appears in 31 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 49 mentions across 29 observed days

What's happening

  • Active exploitation reported across 31 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 26 signals
  • Disclosure: 7 classified signals
  • General: 7 classified signals
  • Peaked 27d ago at 6 mentions (2026-01-28); latest day: 1
  • 49 total mentions across 29 days

Affected systems

Products
fortiosfortiproxyfortiswitchmanagerruggedcom_ape1808ruggedcom_ape1808_firmware

1 version affected across 5 products

Deep dive

Activity timeline49 mentions / 29d
02356Mentions · 2026-01-27: 1Mentions · 2026-01-28: 6Mentions · 2026-01-29: 2Mentions · 2026-01-30: 3Mentions · 2026-01-31: 1Mentions · 2026-02-17: 1Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-17: 2Mentions · 2026-03-20: 1Mentions · 2026-03-23: 2Mentions · 2026-04-08: 4Mentions · 2026-04-09: 3Mentions · 2026-04-10: 2Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-05-21: 1Mentions · 2026-06-15: 2Mentions · 2026-06-16: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-06-29: 1Mentions · 2026-08-18: 1Mentions · 2026-09-28: 1Mentions · 2026-10-08: 1Exploit Tool / Code · 2026-04-08: 1Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-01-29: 2Active Exploitation · 2026-01-30: 2Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-03-10: 2Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-14: 1Active Exploitation · 2026-03-15: 1Active Exploitation · 2026-03-16: 2Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-08: 2Active Exploitation · 2026-04-09: 3Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-09-28: 1Patch / Workaround · 2026-01-28: 5Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-01-28: 4Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 3Technical Details · 2026-01-31: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-29: 1Technical Details · 2026-08-18: 101-2701-2901-3103-1003-1303-1503-1703-2304-0904-1505-2106-1606-2408-1810-08
Signal classification5 categories
Active Exploitation
2858.3%
Disclosure
714.6%
General
714.6%
Patch
510.4%
Exploit
12.1%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-286
Active Exploitation2Disclosure1General2Patch1
2026-01-292
Active Exploitation2
2026-01-303
Active Exploitation1General1Patch1
2026-01-311
Active Exploitation1
2026-02-171
General1
2026-03-102
Active Exploitation2
2026-03-111
Active Exploitation1
2026-03-131
Active Exploitation1
2026-03-141
Active Exploitation1
2026-03-151
Active Exploitation1
2026-03-162
Active Exploitation2
2026-03-172
Active Exploitation1General1
2026-03-201
Active Exploitation1
2026-03-232
Active Exploitation1Patch1
2026-04-084
Active Exploitation2Disclosure1Exploit1
2026-04-093
Active Exploitation3
2026-04-102
Active Exploitation2
2026-04-151
Disclosure1
2026-04-171
General1
2026-05-211
General1
2026-06-152
Disclosure2
2026-06-161
Active Exploitation1
2026-06-232
Disclosure1Patch1
2026-06-241
Patch1
2026-06-291
Active Exploitation1
2026-08-181
Active Exploitation1
2026-09-281
Active Exploitation1
Full discourse20 posts
  • Rapid7@rapid7
    Disclosure

    Rapid7’s IR team was recently engaged around CVE-2025-59718 – a vuln that facilitates SSO login bypass in #Fortinet FortiGate appliances. In a new blog, dive into our investigative methodology, practical detection opportunities & more: https://r-7.co/3Q0CMwo

    Post summary

    Rapid7’s IR team investigated CVE‑2025‑59718, a SSO login bypass vulnerability in Fortinet FortiGate appliances, and published a blog outlining their methodology and detection options.

    01102152.9K
    124.5K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    Hackers Exploit FortiGate Firewalls in Widespread Attacks to Steal Network Credentials Threat actors are primarily abusing several FortiGate vulnerabilities, including CVE-2025-59718, CVE-2025-59719, and the recently patched CVE-2026-24858. These flaws allow unauthorized users to bypass authentication controls and gain administrative-level access to vulnerable firewall devices. https://nuel.ink/qLGpkZ

    Post summary

    The post reports that threat actors are actively exploiting multiple FortiGate vulnerabilities (CVE‑2025‑59718, CVE‑2025‑59719, CVE‑2026‑24858) to bypass authentication and gain administrative access, with one CVE already patched.

    0801171.1K
    1.1K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    BleepingComputer reported on the hacks last week when Fortigates with exposed devices were breached. It was initially thought to be a patch bypass for an auth bypass tracked as CVE-2025-59718. Fortinet later confirmed it to be a new attack pathway. https://www.bleepingcomputer.com/news/security/fortinet-confirms-critical-forticloud-auth-bypass-not-fully-patched/

    Post summary

    Fortinet FortiGate devices were compromised via an authentication bypass identified as CVE-2025-59718. The attacks were reported as active exploitation, with a new attack pathway confirmed and patch status noted as incomplete.

    1101733.7K
    248.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Rapid7 details real-world exploitation of FortiGate CVE-2025-59718, revealing how attackers used SSO bypass vulnerability to establish persistence and pivot into internal networks. Investigation showcases working backwards from internal compromise to edge device IAV. Key findings: • CVE-2025-59718 exploited for SSO authentication bypass on FortiGate appliances - attackers created multiple admin accounts including http://forticloud.com domains • Attack progression: config download → account creation → SSL VPN enablement → internal network access via DHCP-assigned IPs • Post-exploitation: Mimikatz credential harvesting, lateral movement via PsExec/RDP, targeting of domain controllers and backup infrastructure • IOCs include Advanced_IP_Scanner, mimikatz.exe, and 11 malicious IPs (23.163.8[.]21, 45.32.216[.]250, others) • FortiGate logs show configuration changes, new firewall policies, and admin account creation from external IPs Hunt for SSL VPN configuration changes from external IPs, new administrative accounts with suspicious domains, and unexpected DHCP assignments correlating with internal authentication events. Full IOC list and MITRE mappings in the report. #DFIR_Radar

    Post summary

    Rapid7 reports real‑world exploitation of FortiGate CVE-2025-59718 via an SSO bypass, demonstrating attackers achieved persistence, lateral movement, and credential theft across internal networks.

    10033562
    1.7K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    FortiGate機器を入口としたネットワーク侵害について。SentinelOne社報告。CVE-2025-59718、CVE-2025-59719、CVE-2026-24858で例示される既知の脆弱性の悪用。 https://securityaffairs.com/189241/security/attackers-exploit-fortigate-devices-to-access-sensitive-network-information.html

    Post summary

    Attackers have leveraged known CVEs in FortiGate devices to gain access to sensitive network information, as reported by SentinelOne.

    010511.3K
    7.3K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    Patch

    On January 27, Fortinet updated their PSIRT website to include additional affected products, versions and Indicators of Compromise. We recommend organizations patch their Fortinet products and review the suggested security actions: https://www.cyber.gc.ca/en/alerts-advisories/al25-019-vulnerabilities-impacting-fortinet-products-forticloud-sso-login-authentication-bypass-cve-2025-59718-cve-2025-59719

    Post summary

    The advisory highlights the need for patching Fortinet products affected by CVE-2025-59718 and CVE-2025-59719, which are authentication bypass vulnerabilities, and provides a link to detailed remediation steps.

    11040542
    33.9K followersView on X
  • navanem@navanem
    Active Exploitation

    FortiSandbox Critical Flaws Actively Exploited: Patch Now CVE-2025-59718 (CVSS 9.8) and CVE-2025-59719 in Fortinet FortiSandbox are confirmed… Read more: https://www.navanem.com/news/fortinet-fortisandbox-critical-flaws-now-actively-exploited-in-the-wil-mqgx82mz #Fortinet #Fortisandbox #ActiveExploitation #CriticalVulnerability

    Post summary

    The post announces that CVE‑2025‑59718 and CVE‑2025‑59719 in Fortinet FortiSandbox are actively exploited and urges users to apply available patches.

    010404
    5 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    FortiGate のゼロデイ脆弱性 CVE-2026-24858 などを悪用:ネットワーク侵入と資格情報窃取を検出 https://iototsecnews.jp/2026/03/15/fortigate-firewalls-exploited-in-wave-of-attacks-to-breach-networks-and-steal-credentials/ このインシデントが示すのは、複数の深刻な脆弱性が原因となり、被害が広がってしまう状況です。CVE-2025-59718/CVE-2025-59719 を悪用する攻撃者は、認証の仕組みの不備を突き、管理者権限を奪える状態になっていました。また CVE-2026-24858 というゼロデイ脆弱性により、本来は拒否されるべきアカウントでのログインが許可されたことも大きな要因です。 それに加えて、デバイスの設定ファイルが復号しやすい方式で保存されていたことで、内部ネットワークで使用される大切な認証情報が盗み取られてしまいました。こうしたシステム上の弱点や設定の甘さが組み合わさることで、攻撃者に侵入の糸口を与えてしまったと言えます。 #CVE202559718 #CVE202559719 #CVE202624858 #Exploit #FortiGate #Fortinet #Vulnerability

    Post summary

    The article reports active exploitation of FortiGate firewalls via multiple severe vulnerabilities (CVE-2025-59718/19 and CVE-2026-24858), enabling attackers to bypass authentication, gain admin rights, and steal credentials.

    01030234
    484 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 استغلال ثغرات في جدران حماية FortiGate لاختراق الشبكات وسرقة بيانات الاعتماد رصدت عمليات اختراق متعددة استهدفت جدران الحماية FortiGate (NGFW) في أوائل عام 2026، حيث استغل المهاجمون ثغرات حرجة (CVE-2026-24858، CVE-2025-59719، CVE-2025-59718) لزرع موطئ قدم دائم داخل الشبكات المؤسسية. تهدف هذه العمليات إلى سرقة بيانات الاعتماد الحساسة وتوسيع نطاق الوصول غير المصرح به. يُنصح بشدة بتحديث جميع أجهزة FortiGate فورًا وتفعيل آليات المراقبة الأمنية للكشف عن أي مؤشرات اختراق محتملة. 🔗 للمزيد: https://cybersecuritynews.com/fortigate-firewalls-exploited/

    Post summary

    Multiple attackers exploited critical FortiGate firewall vulnerabilities in early 2026 to maintain persistent access and steal credentials, and the text urges immediate device updates.

    00040165
    70 followersView on X
  • Dr.Mashari@GMashari
    Active Exploitation

    📌 استغلال ثغرات في جدران حماية FortiGate لاختراق الشبكات وسرقة بيانات الاعتماد 🛡️ الفئة: هجوم سيبراني 📝 الملخص: رصدت عمليات اختراق متعددة استهدفت جدران الحماية FortiGate (NGFW) في أوائل عام 2026، حيث استغل المهاجمون ثغرات حرجة (CVE-2026-24858، CVE-2025-59719، CVE-2025-59718) لزرع موطئ قدم دائم داخل الشبكات المؤسسية. تهدف هذه العمليات إلى سرقة بيانات الاعتماد الحساسة وتوسيع نطاق الوصول غير المصرح به. يُنصح بشدة بتحديث جميع أجهزة FortiGate فورًا وتفعيل آليات المراقبة الأمنية للكشف عن أي مؤشرات اختراق محتملة. 🗓️ تاريخ النشر: 15/03/2026 🔗 للمزيد: https://cybersecuritynews.com/fortigate-firewalls-exploited/

    Post summary

    The post reports real‑world attacks using CVE-2026-24858, CVE-2025-59719, and CVE-2025-59718 against FortiGate firewalls, and urges immediate patching.

    01020175
    9.0K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    FortiBleed の積極的な悪用:FortiGate デバイスから認証情報を収集 – Fortinet https://iototsecnews.jp/2026/06/22/fortibleed-fortinet-warns-of-active-credential-harvesting-campaign-targeting-fortigate-devices/ FortiGate デバイスを狙った認証情報の奪取事案が多発しています。この問題の背景には、過去の脆弱性 (CVE-2026-24858/CVE-2025-59718/CVE-2025-59719) で漏洩した情報の再利用や、多要素認証の未導入といった管理上の隙があります。悪用された場合には、コンフィグの改竄や内部ネットワークへの侵入といった深刻な影響が生じます。対応策として、まずは接続パスワードの速やかなリセットと多要素認証の導入を進めてください。また、不要な外部公開を控え、不審なログがないか定期的に点検すべきだと、この記事は指摘しています。 #CyberAttack #Exploit #FortiBleed #FortiGate #Fortinet #Vulnerability

    Post summary

    FortiGate devices are being actively targeted for credential harvesting via CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719. Immediate remediation—reset passwords, enable MFA, limit external exposure, and monitor logs—is urged.

    01010214
    500 followersView on X
  • RST Cloud@rst_cloud
    Patch

    #threatreport #LowCompleteness Analysis of Single Sign-On Abuse on FortiOS | 22-01-2026 Source: https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios Key details below ↓ 🎯Victims: Fortigate devices 🔓CVEs: CVE-2025-59719 \[[Vulners](https://vulners.com/cve/CVE-2025-59719)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortiweb (le7.4.9, le7.6.4, 8.0.0) CVE-2025-59718 \[[Vulners](https://vulners.com/cve/CVE-2025-59718)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortiproxy (<7.0.22, <7.2.15, <7.4.11, <7.6.4) - fortinet fortiswitchmanager (<7.0.6, <7.2.7) - fortinet fortios (<7.0.18, <7.2.12, <7.4.9, <7.6.4) 🤖LLM extracted TTPs:` T1098, T1190 🧨IOCs: - Email: 2 - IP: 4 - File: 1 #threatreport: In December 2025, Fortinet identified two critical vulnerabilities in their FortiCloud single sign-on (SSO) feature, designated as CVE-2025-59718 and CVE-2025-59719. These vulnerabilities, discovered during an internal code audit, allow for potential bypass of security mechanisms, increasing the risk of unauthorized access to sensitive functionalities. The advisory issued by Fortinet also includes indicators of compromise (IOCs) to help customers identify any attempts of malicious activity within their systems. The analysis highlights a specific log entry tied to malicious login events, underscoring the importance of monitoring access logs to detect unauthorized entry attempts. To mitigate risks associated with administrative access, it is advisable to implement controls that restrict access based on known malicious IP addresses, while only permitting HTTPS management from specific subnets, such as 10.10.10.0/24. This approach emphasizes the necessity of tailoring security measures to the respective network environment. In response to potential exploitation of the identified vulnerabilities, organizations are urged to ensure their devices are updated to the latest firmware version, specifically version 7.6, which encompasses enhanced security features. Additionally, it is critical to restore configurations from verified clean backups or conduct audits to identify unauthorized modifications, paying close attention to any unexpected administrator accounts or alterations in VPN settings. Given the heightened risks, configuration changes should be treated as compromised, leading to the urgent need to rotate credentials, including those for LDAP or Active Directory accounts that may be integrated with FortiGate devices. These steps are essential to safeguard against further exploitation and ensure the integrity of the network security posture.

    Post summary

    Fortinet released a threat report on two critical SSO vulnerabilities (CVE‑2025‑59718 and CVE‑2025‑59719), providing CVSS scores and exploitation evidence, and urged customers to upgrade to firmware 7.6 and apply other remediation measures.

    10010122
    682 followersView on X
  • セキュリティ対策Lab@securityLab_jp

    FBI、FortiBleedを悪用したサイバー攻撃を再警告―脆弱性:CVE-2026-24858、CVE-2025-59718、CVE-2025-59719 https://rocket-boys.co.jp/security-measures-lab/fbi-fortibleed-fortigate-lockout-ransomware/ #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース

    00001583
    3.4K followersView on X
  • Lupovis@LupovisDefence
    Active Exploitation

    Fortinet SAML auth-bypass attacks on our decoys stepped up sharply in June and are surging again this week. CVE-2025-59718 (FortiOS/FortiProxy) and CVE-2025-59719 (FortiWeb): same flaw, a forged SAML response bypasses FortiCloud SSO login. CVSS 9.1. A typical day ran ~50 detections through May, then stepped up to ~272/day from June (5.4x) and held all summer. This week it surged again, ~207 to ~352/day over Aug 14-17, peaking at 374. The probes hit POST /logincheck, the Fortinet SSL-VPN / SSO login endpoint. Patch per Fortinet FG-IR-25-647 and watch that path for forged SAML responses. For the IOC list http://insights.lupovis.io Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-647 #Fortinet #FortiOS #FortiWeb #CVE #ThreatIntel #InfoSec

    Post summary

    CVE‑2025‑59718/59719 is actively exploited through forged SAML responses against Fortinet products, with attack volumes spiking to over 300 per day. Fortinet has released patch FG‑IR‑25‑647 to mitigate the vulnerability.

    00010100
    576 followersView on X
  • GoCocoaAI@GoCocoaAI
    Patch

    86,644 FortiGate firewalls. 194 countries. Admin and VPN credentials, validated and packaged. FortiBleed surfaced June 13 — and the window was open before anyone noticed. One correction worth making upfront: FortiBleed is not a CVE. It's a credential-harvesting campaign — brute-force, dictionary attacks, credential stuffing against internet-facing FortiGate devices with weak password hygiene and no MFA. There is no buffer overflow to patch. There is no zero-day to wait on. The reframe matters operationally because you're not in a patching race. You're in a credential-recovery race. Different clock. Different playbook. Samsung, Siemens, Oracle, DHL, Accenture, Infosys, Foxconn, and a Turkish NATO contractor are confirmed in the dataset. The campaign is attributed to a Russian-speaking cybercriminal syndicate. CISA and NCSC both issued emergency advisories June 18. The dataset was live before the June 13 disclosure — assume access may have occurred weeks prior. PHASE 1 — IMMEDIATE (tonight, before anything else) Check your exposure first. Run your FortiGate-facing domains through the SOCRadar FortiBleed Checker (http://socradar.io/free-tools/fortibleed) and the Hudson Rock checker (http://hudsonrock.com/fortinet). If either flags your domain — you are confirmed compromised. If neither flags you — proceed anyway. The dataset grew after disclosure. Clean today does not mean clean tomorrow. Then kill every active session. Do not triage. Do not selectively terminate. Kill everything — SSL VPN tunnels, admin sessions, all of it. Assume every active session is hostile until rotated credentials are in place. Then reset every credential that has ever touched the FortiGate admin interface or VPN portal. Local admin accounts. LDAP and Active Directory service accounts used for VPN auth. FortiCloud SSO credentials. API tokens and certificates. No exceptions for "trusted" accounts — the entire point of credential stuffing is reuse, and eliminating reuse is the only durable answer here. Generate unique 20+ character passwords per account. PHASE 2 — ENFORCE MFA (within 24 hours) The absence of MFA is the root cause. This is the fix that closes the campaign vector. Enable MFA on the FortiGate admin interface. FortiToken Mobile is free for up to 2 tokens per device. There is no argument for leaving admin surfaces unprotected after this week. Enable MFA on the SSL VPN portal as well. If your IdP is Azure AD / Entra ID or Okta, configure SAML authentication to push MFA through the IdP — more scalable, single policy surface, harder to bypass. We are nothing if not consistent: the two controls that would have prevented most of this campaign are the same two controls that appear in every post-mortem from the last decade. Password hygiene and MFA. The infosec drinking game continues. PHASE 3 — HARDEN THE PERIMETER (within 72 hours) Restrict management plane access to known IP ranges only. The management interface should never be internet-facing. If it is — that changes tonight, not this quarter. Implement account lockout and login rate limiting: five failed attempts, five-minute lockout. That configuration alone would have broken most of the brute-force tooling used in this campaign. Apply all pending FortiOS patches. FortiBleed has no CVE, but the associated cluster does — CVE-2026-24858 (Critical, FortiCloud SSO authentication bypass), CVE-2025-59718 (High, FortiOS management plane privilege escalation), and CVE-2025-59719 (High, FortiGate exported config credential exposure). Check your FortiOS version against the Fortinet PSIRT portal at http://fortiguard.com/psirt and patch to the latest stable release in your branch. PHASE 4 — DETECT AND HUNT (start now, run ongoing) The dataset was live before June 13. Hunt back 60 days minimum. Look for login successes from IPs outside your known admin ranges. Flag admin sessions outside business hours. Flag any config export events. A sustained sequence of failed admin login events from a single source IP is your brute-force indicator — alert on it. The stolen FortiGate credentials are likely being tested against your broader estate right now: Office 365, Azure AD, VPN, cloud consoles. Check your IdP logs for login attempts using service account credentials, MFA fatigue and push-bombing patterns, and new device registrations from unfamiliar ASNs. PHASE 5 — VERIFY AND REPORT The Fortinet PSIRT blog is the authoritative source and may update as the campaign evolves. If your organization is a named entity in the leaked dataset — loop in counsel. Breach notification obligations under GDPR, UK DPA 2018, or applicable state law don't wait for your remediation timeline to close. And if you have business relationships with any of the confirmed named organizations and share network access or credentials — treat their credentials as compromised until they confirm remediation. MITRE D3FEND countermeasures, in priority order: M1032 (Multi-Factor Authentication) and M1027 (Password Policies) are immediate — they are the root cause mitigations. M1035 (management plane isolation) and M1036 (account lockout and rate limiting) within 24 hours. M1030 (network segmentation, isolate VPN concentrators) within 72 hours. Your perimeter is either already clean or already breached. The checker tells you which. The playbook tells you what to do either way. Act accordingly.

    Post summary

    The text outlines an active credential‑harvesting campaign (FortiBleed) and provides a detailed remediation playbook, including session termination, MFA rollout, password hygiene, lockout policies, and patching of related CVEs, with practical checkers and advisories to secure FortiGate environments.

    10000119
    34 followersView on X
  • Martin Bergo@MartinBergo
    General

    @LowLevelTweets CVE-2025-25249 / CVE-2025-59718 Will there be more? 👀

    Post summary

    The tweet merely lists two CVE identifiers and wonders if more exist, providing no further context or technical details.

    00010873
    41 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2025-59718: FortiGate SSO Login Bypass — Detection and Containment Guide "Rapid7's recent Incident Response (IR) engagement confirms what security teams…" 🔗 https://securityarsenal.com/blog/cve-2025-59718-fortigate-sso-login-bypass-detection-and-containment-guide #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonitoring

    Post summary

    The tweet advertises a detection and containment guide for CVE-2025-59718 (FortiGate SSO Login Bypass) without providing proof of concept, exploit code, or active exploitation evidence.

    01000518
    10 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness FortiGate CVE-2025-59718 Exploitation: Incident Response Findings | 08-04-2026 Source: https://www.rapid7.com/blog/post/ve-fortigate-cve-2025-59718-exploitation-incident-response-ir-findings Key details below ↓ 🧑‍💻Actors/Campaigns: Akira_ransomware 💀Threats: Mimikatz_tool, Credential_dumping_technique, Advanced-port-scanner_tool, Akira_ransomware, 🎯Victims: Fortigate appliances, Firewalls, Internal network hosts, Virtualization platforms, Domain controllers, Backup infrastructure 🏭Industry: Critical_infrastructure 🔓CVEs: CVE-2025-59718 \[[Vulners](https://vulners.com/cve/CVE-2025-59718)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortiproxy (<7.0.22, <7.2.15, <7.4.11, <7.6.4) - fortinet fortiswitchmanager (<7.0.6, <7.2.7) - fortinet fortios (<7.0.18, <7.2.12, <7.4.9, <7.6.4) 📚TTPs: ⚔️Tactics: 7 🛠️Technics: 9 🧨IOCs: - IP: 12 - File: 6 - Domain: 1 💽Software: PsExec, Windows Registry, sysinternals, Velociraptor #threatreport: The exploitation of CVE-2025-59718, a vulnerability in FortiGate appliances, has been analyzed following an incident investigated by Rapid7's Incident Response team. This vulnerability allows for a single sign-on (SSO) login bypass, which the attackers exploited in December 2025. After gaining initial access, attackers maintained a low profile, compromising additional firewalls and laterally moving into the internal network. The incident is characterized by systematic credential discovery and the use of legitimate credentials for further access, exemplified by the use of Mimikatz to harvest admin credentials. The investigation revealed that attackers leveraged common administrative tools and methods for lateral movement, particularly utilizing PsExec and Microsoft Remote Desktop Protocol (RDP). Their primary targets were high-value systems such as virtualization platforms, domain controllers, and backup servers, which could facilitate privilege escalation or unauthorized access to sensitive data. Notably, the attack was initiated from an internal IP address associated with the FortiGate device, despite no legitimate SSL VPN configurations being present in the environment. This discrepancy prompted further scrutiny of the FortiGate device. Upon examination, investigators identified multiple unauthorized configuration changes, including the activation of the SSL VPN component and the creation of several administrative and local accounts linked to external email domains. This activity was indicative of an ongoing intrusion, with attackers creating persistence mechanisms and modifying firewall rules to secure their access. The first authentication event was traced back to a time when the attackers began establishing their foothold, approximately two weeks prior to detectable malicious activities. The attack methodology was consistent with multiple MITRE ATT&CK techniques, including exploitation of public-facing applications, creation of accounts for persistence, and the use of valid credentials for lateral movement and initial access. The use of tools like Advanced_Port_Scanner for reconnaissance and the execution of PsExec for lateral movement further illustrate the breadth of techniques employed by the attackers. To mitigate such vulnerabilities, continuous monitoring of edge devices like firewalls and VPN appliances is essential. Implementing real-time audit trails can help close visibility gaps, providing crucial insights into attempts at configuration changes, connection attempts, and potential exploit signatures. This layered approach can enhance defenses against future exploitative actions.

    Post summary

    Rapid7’s incident response team confirms real‑world exploitation of CVE‑2025‑59718 in FortiGate appliances via an SSO bypass, with attackers using Mimikatz and PsExec for lateral movement and persistence.

    00010410
    629 followersView on X
  • bigmacd@bigmacd16684
    Patch

    CVE-2025-59718 added to CISA's KEV catalog in late Jan 2026. Fortinet suspended FortiCloud SSO, then released a firmware patch. Apply patch ASAP, rotate all LDAP and AD. #cybersecurity

    Post summary

    The post alerts that CVE‑2025‑59718 has been added to CISA’s KEV catalog; Fortinet has released a firmware patch and urges users to apply it immediately while also rotating LDAP and AD credentials.

    10000102
    3 followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    Attackers exploited critical CVE-2025-59718 and CVE-2025-59719 vulnerabilities in FortiGate NGFWs from Dec 2025 to Feb 2026. Issues were rated 9.8 by SentinelOne due to improper cryptographic handling. #cybersecurity

    Post summary

    The post confirms attackers actively exploited FortiGate NGFW vulnerabilities CVE-2025-59718 and CVE-2025-59719 between December 2025 and February 2026, highlighting an improper cryptographic handling flaw rated 9.8 by SentinelOne.

    10000144
    3 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---
Appfortinetfortiswitchmanager---
HWsiemensruggedcom_ape1808---
OSsiemensruggedcom_ape1808_firmware---

Explore more