CVE-2025-59719Active Exploitation(fortinet / fortiweb)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortiweb systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Active exploitation appears in 14 classified signals
  • Patch or workaround signal is available
  • 22 mentions across 17 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 14 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 12 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 15d ago at 2 mentions (2026-01-28); latest day: 1
  • 22 total mentions across 17 days

Affected systems

Vendors
Products
fortiweb

1 version affected across 1 product

Deep dive

Activity timeline22 mentions / 17d
01122Mentions · 2026-01-27: 1Mentions · 2026-01-28: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Mentions · 2026-06-15: 2Mentions · 2026-06-16: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-06-29: 1Mentions · 2026-08-13: 2Mentions · 2026-08-18: 1Mentions · 2026-09-28: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-16: 2Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-09-28: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-09-28: 1Technical Details · 2026-01-28: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-18: 101-2701-2803-1003-1103-1303-1603-1703-2003-2306-1506-1606-2306-2406-2908-1308-1809-28
Signal classification5 categories
Active Exploitation
1359.1%
Disclosure
418.2%
General
29.1%
Patch
29.1%
Exploit
14.5%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-282
General1Patch1
2026-03-101
Active Exploitation1
2026-03-111
Active Exploitation1
2026-03-131
Active Exploitation1
2026-03-162
Active Exploitation2
2026-03-171
Active Exploitation1
2026-03-201
Active Exploitation1
2026-03-231
Active Exploitation1
2026-06-152
Disclosure2
2026-06-161
Active Exploitation1
2026-06-232
Disclosure1Patch1
2026-06-241
Active Exploitation1
2026-06-291
Active Exploitation1
2026-08-132
Exploit1General1
2026-08-181
Active Exploitation1
2026-09-281
Active Exploitation1
Full discourse20 posts
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    Hackers Exploit FortiGate Firewalls in Widespread Attacks to Steal Network Credentials Threat actors are primarily abusing several FortiGate vulnerabilities, including CVE-2025-59718, CVE-2025-59719, and the recently patched CVE-2026-24858. These flaws allow unauthorized users to bypass authentication controls and gain administrative-level access to vulnerable firewall devices. https://nuel.ink/qLGpkZ

    Post summary

    The article reports that attackers are leveraging multiple FortiGate vulnerabilities, including CVE-2025-59718/59719 and a recently patched CVE-2026-24858, to escape authentication and gain admin access. While a patch exists for one CVE, the attacks remain widespread.

    0801171.1K
    1.1K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    FortiGate機器を入口としたネットワーク侵害について。SentinelOne社報告。CVE-2025-59718、CVE-2025-59719、CVE-2026-24858で例示される既知の脆弱性の悪用。 https://securityaffairs.com/189241/security/attackers-exploit-fortigate-devices-to-access-sensitive-network-information.html

    Post summary

    SentinelOne reports attackers exploiting FortiGate devices via CVE-2025-59718, CVE-2025-59719, and CVE-2026-24858, indicating active exploitation in the wild.

    010511.3K
    7.3K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    Patch

    On January 27, Fortinet updated their PSIRT website to include additional affected products, versions and Indicators of Compromise. We recommend organizations patch their Fortinet products and review the suggested security actions: https://www.cyber.gc.ca/en/alerts-advisories/al25-019-vulnerabilities-impacting-fortinet-products-forticloud-sso-login-authentication-bypass-cve-2025-59718-cve-2025-59719

    Post summary

    Fortinet’s PSIRT update for CVE‑2025‑59718 and CVE‑2025‑59719 lists affected products, IOCs, and urges patching and review of security actions.

    11040542
    33.9K followersView on X
  • navanem@navanem
    Active Exploitation

    FortiSandbox Critical Flaws Actively Exploited: Patch Now CVE-2025-59718 (CVSS 9.8) and CVE-2025-59719 in Fortinet FortiSandbox are confirmed… Read more: https://www.navanem.com/news/fortinet-fortisandbox-critical-flaws-now-actively-exploited-in-the-wil-mqgx82mz #Fortinet #Fortisandbox #ActiveExploitation #CriticalVulnerability

    Post summary

    Newly disclosed Fortinet FortiSandbox CVEs (CVE-2025-59718, CVE-2025-59719) are actively exploited in the wild, and users are urged to apply patches immediately.

    010404
    5 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    FortiGate のゼロデイ脆弱性 CVE-2026-24858 などを悪用:ネットワーク侵入と資格情報窃取を検出 https://iototsecnews.jp/2026/03/15/fortigate-firewalls-exploited-in-wave-of-attacks-to-breach-networks-and-steal-credentials/ このインシデントが示すのは、複数の深刻な脆弱性が原因となり、被害が広がってしまう状況です。CVE-2025-59718/CVE-2025-59719 を悪用する攻撃者は、認証の仕組みの不備を突き、管理者権限を奪える状態になっていました。また CVE-2026-24858 というゼロデイ脆弱性により、本来は拒否されるべきアカウントでのログインが許可されたことも大きな要因です。 それに加えて、デバイスの設定ファイルが復号しやすい方式で保存されていたことで、内部ネットワークで使用される大切な認証情報が盗み取られてしまいました。こうしたシステム上の弱点や設定の甘さが組み合わさることで、攻撃者に侵入の糸口を与えてしまったと言えます。 #CVE202559718 #CVE202559719 #CVE202624858 #Exploit #FortiGate #Fortinet #Vulnerability

    Post summary

    The article reports that FortiGate firewalls were actively compromised using CVE‑2026‑24858 and CVE‑2025‑59718/59719, leading to credential theft and network intrusion, with no patch or PoC details provided.

    01030234
    484 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 استغلال ثغرات في جدران حماية FortiGate لاختراق الشبكات وسرقة بيانات الاعتماد رصدت عمليات اختراق متعددة استهدفت جدران الحماية FortiGate (NGFW) في أوائل عام 2026، حيث استغل المهاجمون ثغرات حرجة (CVE-2026-24858، CVE-2025-59719، CVE-2025-59718) لزرع موطئ قدم دائم داخل الشبكات المؤسسية. تهدف هذه العمليات إلى سرقة بيانات الاعتماد الحساسة وتوسيع نطاق الوصول غير المصرح به. يُنصح بشدة بتحديث جميع أجهزة FortiGate فورًا وتفعيل آليات المراقبة الأمنية للكشف عن أي مؤشرات اختراق محتملة. 🔗 للمزيد: https://cybersecuritynews.com/fortigate-firewalls-exploited/

    Post summary

    The post reports confirmed active exploitation of FortiGate firewalls via CVE‑2026‑24858, CVE‑2025‑59719, and CVE‑2025‑59718, and urges immediate patching and monitoring.

    00040165
    70 followersView on X
  • Dr.Mashari@GMashari
    Active Exploitation

    📌 استغلال ثغرات في جدران حماية FortiGate لاختراق الشبكات وسرقة بيانات الاعتماد 🛡️ الفئة: هجوم سيبراني 📝 الملخص: رصدت عمليات اختراق متعددة استهدفت جدران الحماية FortiGate (NGFW) في أوائل عام 2026، حيث استغل المهاجمون ثغرات حرجة (CVE-2026-24858، CVE-2025-59719، CVE-2025-59718) لزرع موطئ قدم دائم داخل الشبكات المؤسسية. تهدف هذه العمليات إلى سرقة بيانات الاعتماد الحساسة وتوسيع نطاق الوصول غير المصرح به. يُنصح بشدة بتحديث جميع أجهزة FortiGate فورًا وتفعيل آليات المراقبة الأمنية للكشف عن أي مؤشرات اختراق محتملة. 🗓️ تاريخ النشر: 15/03/2026 🔗 للمزيد: https://cybersecuritynews.com/fortigate-firewalls-exploited/

    Post summary

    The article reports confirmed, active exploitation of critical FortiGate firewall CVEs in early 2026, urges immediate patching, and provides basic vulnerability details.

    01020175
    9.0K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    FortiBleed の積極的な悪用:FortiGate デバイスから認証情報を収集 – Fortinet https://iototsecnews.jp/2026/06/22/fortibleed-fortinet-warns-of-active-credential-harvesting-campaign-targeting-fortigate-devices/ FortiGate デバイスを狙った認証情報の奪取事案が多発しています。この問題の背景には、過去の脆弱性 (CVE-2026-24858/CVE-2025-59718/CVE-2025-59719) で漏洩した情報の再利用や、多要素認証の未導入といった管理上の隙があります。悪用された場合には、コンフィグの改竄や内部ネットワークへの侵入といった深刻な影響が生じます。対応策として、まずは接続パスワードの速やかなリセットと多要素認証の導入を進めてください。また、不要な外部公開を控え、不審なログがないか定期的に点検すべきだと、この記事は指摘しています。 #CyberAttack #Exploit #FortiBleed #FortiGate #Fortinet #Vulnerability

    Post summary

    Fortinet reports an ongoing credential‑harvesting campaign against FortiGate devices via CVE‑2026‑24858 and related CVEs, recommending password resets and MFA implementation.

    01010214
    500 followersView on X
  • RST Cloud@rst_cloud
    Patch

    #threatreport #LowCompleteness Analysis of Single Sign-On Abuse on FortiOS | 22-01-2026 Source: https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios Key details below ↓ 🎯Victims: Fortigate devices 🔓CVEs: CVE-2025-59719 \[[Vulners](https://vulners.com/cve/CVE-2025-59719)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortiweb (le7.4.9, le7.6.4, 8.0.0) CVE-2025-59718 \[[Vulners](https://vulners.com/cve/CVE-2025-59718)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortiproxy (<7.0.22, <7.2.15, <7.4.11, <7.6.4) - fortinet fortiswitchmanager (<7.0.6, <7.2.7) - fortinet fortios (<7.0.18, <7.2.12, <7.4.9, <7.6.4) 🤖LLM extracted TTPs:` T1098, T1190 🧨IOCs: - Email: 2 - IP: 4 - File: 1 #threatreport: In December 2025, Fortinet identified two critical vulnerabilities in their FortiCloud single sign-on (SSO) feature, designated as CVE-2025-59718 and CVE-2025-59719. These vulnerabilities, discovered during an internal code audit, allow for potential bypass of security mechanisms, increasing the risk of unauthorized access to sensitive functionalities. The advisory issued by Fortinet also includes indicators of compromise (IOCs) to help customers identify any attempts of malicious activity within their systems. The analysis highlights a specific log entry tied to malicious login events, underscoring the importance of monitoring access logs to detect unauthorized entry attempts. To mitigate risks associated with administrative access, it is advisable to implement controls that restrict access based on known malicious IP addresses, while only permitting HTTPS management from specific subnets, such as 10.10.10.0/24. This approach emphasizes the necessity of tailoring security measures to the respective network environment. In response to potential exploitation of the identified vulnerabilities, organizations are urged to ensure their devices are updated to the latest firmware version, specifically version 7.6, which encompasses enhanced security features. Additionally, it is critical to restore configurations from verified clean backups or conduct audits to identify unauthorized modifications, paying close attention to any unexpected administrator accounts or alterations in VPN settings. Given the heightened risks, configuration changes should be treated as compromised, leading to the urgent need to rotate credentials, including those for LDAP or Active Directory accounts that may be integrated with FortiGate devices. These steps are essential to safeguard against further exploitation and ensure the integrity of the network security posture.

    Post summary

    Fortinet’s threat report discloses two critical SSO bypass CVEs (CVE‑2025‑59718 and CVE‑2025‑59719), provides IOCs and mitigation guidance—including patching to firmware 7.6—without releasing a PoC or indicating active exploitation.

    10010122
    682 followersView on X
  • Lupovis@LupovisDefence
    Active Exploitation

    Fortinet SAML auth-bypass attacks on our decoys stepped up sharply in June and are surging again this week. CVE-2025-59718 (FortiOS/FortiProxy) and CVE-2025-59719 (FortiWeb): same flaw, a forged SAML response bypasses FortiCloud SSO login. CVSS 9.1. A typical day ran ~50 detections through May, then stepped up to ~272/day from June (5.4x) and held all summer. This week it surged again, ~207 to ~352/day over Aug 14-17, peaking at 374. The probes hit POST /logincheck, the Fortinet SSL-VPN / SSO login endpoint. Patch per Fortinet FG-IR-25-647 and watch that path for forged SAML responses. For the IOC list http://insights.lupovis.io Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-647 #Fortinet #FortiOS #FortiWeb #CVE #ThreatIntel #InfoSec

    Post summary

    The post reports widespread exploitation of FortiOS/FortiProxy and FortiWeb via forged SAML responses, with detection counts surging in June and August; a Fortinet patch FG‑IR‑25‑647 is recommended.

    00010100
    576 followersView on X
  • CVE Brief@DailyCVEBrief
    General

    LOOK BACK — CVE-2025-59719 and its sibling were one FortiCloud SSO signature-verification flaw, one advisory, two CVE IDs. Attackers came through FortiGate, so the other ID got the exploitation reports and the KEV listing. This one got neither. https://t.co/Ew3S49Q93G

    Post summary

    The tweet mentions the CVE as part of a FortiCloud SSO flaw, but does not provide evidence of exploitation, patches, or PoC details, making it a general notice.

    1000058
    27 followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    86,644 FortiGate firewalls. 194 countries. Admin and VPN credentials, validated and packaged. FortiBleed surfaced June 13 — and the window was open before anyone noticed. One correction worth making upfront: FortiBleed is not a CVE. It's a credential-harvesting campaign — brute-force, dictionary attacks, credential stuffing against internet-facing FortiGate devices with weak password hygiene and no MFA. There is no buffer overflow to patch. There is no zero-day to wait on. The reframe matters operationally because you're not in a patching race. You're in a credential-recovery race. Different clock. Different playbook. Samsung, Siemens, Oracle, DHL, Accenture, Infosys, Foxconn, and a Turkish NATO contractor are confirmed in the dataset. The campaign is attributed to a Russian-speaking cybercriminal syndicate. CISA and NCSC both issued emergency advisories June 18. The dataset was live before the June 13 disclosure — assume access may have occurred weeks prior. PHASE 1 — IMMEDIATE (tonight, before anything else) Check your exposure first. Run your FortiGate-facing domains through the SOCRadar FortiBleed Checker (http://socradar.io/free-tools/fortibleed) and the Hudson Rock checker (http://hudsonrock.com/fortinet). If either flags your domain — you are confirmed compromised. If neither flags you — proceed anyway. The dataset grew after disclosure. Clean today does not mean clean tomorrow. Then kill every active session. Do not triage. Do not selectively terminate. Kill everything — SSL VPN tunnels, admin sessions, all of it. Assume every active session is hostile until rotated credentials are in place. Then reset every credential that has ever touched the FortiGate admin interface or VPN portal. Local admin accounts. LDAP and Active Directory service accounts used for VPN auth. FortiCloud SSO credentials. API tokens and certificates. No exceptions for "trusted" accounts — the entire point of credential stuffing is reuse, and eliminating reuse is the only durable answer here. Generate unique 20+ character passwords per account. PHASE 2 — ENFORCE MFA (within 24 hours) The absence of MFA is the root cause. This is the fix that closes the campaign vector. Enable MFA on the FortiGate admin interface. FortiToken Mobile is free for up to 2 tokens per device. There is no argument for leaving admin surfaces unprotected after this week. Enable MFA on the SSL VPN portal as well. If your IdP is Azure AD / Entra ID or Okta, configure SAML authentication to push MFA through the IdP — more scalable, single policy surface, harder to bypass. We are nothing if not consistent: the two controls that would have prevented most of this campaign are the same two controls that appear in every post-mortem from the last decade. Password hygiene and MFA. The infosec drinking game continues. PHASE 3 — HARDEN THE PERIMETER (within 72 hours) Restrict management plane access to known IP ranges only. The management interface should never be internet-facing. If it is — that changes tonight, not this quarter. Implement account lockout and login rate limiting: five failed attempts, five-minute lockout. That configuration alone would have broken most of the brute-force tooling used in this campaign. Apply all pending FortiOS patches. FortiBleed has no CVE, but the associated cluster does — CVE-2026-24858 (Critical, FortiCloud SSO authentication bypass), CVE-2025-59718 (High, FortiOS management plane privilege escalation), and CVE-2025-59719 (High, FortiGate exported config credential exposure). Check your FortiOS version against the Fortinet PSIRT portal at http://fortiguard.com/psirt and patch to the latest stable release in your branch. PHASE 4 — DETECT AND HUNT (start now, run ongoing) The dataset was live before June 13. Hunt back 60 days minimum. Look for login successes from IPs outside your known admin ranges. Flag admin sessions outside business hours. Flag any config export events. A sustained sequence of failed admin login events from a single source IP is your brute-force indicator — alert on it. The stolen FortiGate credentials are likely being tested against your broader estate right now: Office 365, Azure AD, VPN, cloud consoles. Check your IdP logs for login attempts using service account credentials, MFA fatigue and push-bombing patterns, and new device registrations from unfamiliar ASNs. PHASE 5 — VERIFY AND REPORT The Fortinet PSIRT blog is the authoritative source and may update as the campaign evolves. If your organization is a named entity in the leaked dataset — loop in counsel. Breach notification obligations under GDPR, UK DPA 2018, or applicable state law don't wait for your remediation timeline to close. And if you have business relationships with any of the confirmed named organizations and share network access or credentials — treat their credentials as compromised until they confirm remediation. MITRE D3FEND countermeasures, in priority order: M1032 (Multi-Factor Authentication) and M1027 (Password Policies) are immediate — they are the root cause mitigations. M1035 (management plane isolation) and M1036 (account lockout and rate limiting) within 24 hours. M1030 (network segmentation, isolate VPN concentrators) within 72 hours. Your perimeter is either already clean or already breached. The checker tells you which. The playbook tells you what to do either way. Act accordingly.

    Post summary

    The text reports that FortiBleed, a credential‑harvesting campaign, was actively exploited in the wild, debunks any CVE claim, and outlines immediate patching and MFA remediation steps.

    10000119
    34 followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    Attackers exploited critical CVE-2025-59718 and CVE-2025-59719 vulnerabilities in FortiGate NGFWs from Dec 2025 to Feb 2026. Issues were rated 9.8 by SentinelOne due to improper cryptographic handling. #cybersecurity

    Post summary

    The post reports that attackers have actively exploited CVE-2025-59718 and CVE-2025-59719 in FortiGate NGFWs, highlighting a real‑world exploitation scenario.

    10000144
    3 followersView on X
  • CyberPrism@CyberPrismApp
    Active Exploitation

    threat actors compromised FortiGate Next-Generation Firewall (NGFW) appliances to gain initial access to corporate networks. Attackers exploited vulnerabilities (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) or weak credentials to gain administrative access https://drive.google.com/file/d/1jtv2gLTWbbB1TPyIZe5VHQXXF44RDO5V/view?usp=drive_link

    Post summary

    Threat actors exploited FortiGate NGFW vulnerabilities (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) or weak credentials to gain administrative access to corporate networks.

    10000150
    12 followersView on X
  • Centre canadien pour la cybersécurité@centrecyber_ca
    General

    Fortinet a mis à jour le site Web de son équipe d'intervention en cas d'incident relatif à la sécurité des produits pour ajouter une liste de nouvelles versions et de nouveaux produits touchés, ainsi que de nouveaux indicateurs de compromission. https://www.cyber.gc.ca/fr/alertes-avis/al25-019-vulnerabilites-visant-produits-fortinet-contournement-lauthentification-connexion-forticloud-sso-cve-2025-59718-cve-2025-59719

    Post summary

    Fortinet has updated its incident response webpage to list new affected versions, products, and indicators of compromise for CVE‑2025‑59718 and CVE‑2025‑59719, without providing any PoC, exploit details, patch information, or active exploitation claims.

    10000103
    3.8K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Threat actors are exploiting two critical Fortinet flaws, tracked as CVE-2025-59718 and CVE-2025-59719, days after patch release, impacting multiple Fortinet products. Threat actors started exploiting two critical flaws... https://f.mtr.cool/ekvuad0o5y

    Post summary

    The text reports that threat actors are actively exploiting two critical Fortinet vulnerabilities (CVE-2025-59718 and CVE-2025-59719) in the wild shortly after patches were released.

    0000073
    2.1K followersView on X
  • CVE Brief@DailyCVEBrief
    Exploit

    Full Look Back: the feature that turned itself on at registration, why two firms called the public exploit code non-functional, and the January sequel that hit fully patched devices. https://cvebrief.com/cve/CVE-2025-59719/ https://t.co/nJL2AfynKf

    Post summary

    The tweet highlights CVE-2025-59719, notes that a public exploit was deemed non‑functional by firms, and points to a January incident that affected fully patched devices—suggesting the CVE has seen real‑world exploitation but provides little technical detail.

    0000042
    27 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Fortinet、FortiBleedに公式見解 過去の認証バイパス 脆弱性からの漏洩-(CVE-2026-24858・CVE-2025-59718・CVE-2025-59719) https://rocket-boys.co.jp/security-measures-lab/fortigate-credential-reuse-cve-2026-24858/ #セキュリティ対策Lab #security #securitynews #cyberattack #incident #databreach

    Post summary

    The article announces Fortinet’s official stance on certain CVEs that led to data leaks, but it does not provide proof of exploitation, exploit code, or remediation details.

    00000174
    439 followersView on X
  • Andre Gironda@AndreGironda
    Disclosure

    TrueSec, FortiNet SSO vulnerability CVE-2025-59718 and CVE-2025-59719 leading to system compromise -- https://www.truesec.com/hub/blog/vulnerability-cve-2025-59718-and-cve-2025-59719

    Post summary

    TrueSec’s blog post announces FortiNet SSO vulnerabilities CVE‑2025‑59718 and CVE‑2025‑59719 that could lead to system compromise, but no PoC, exploit, or patch information is provided here.

    0000091
    3.8K followersView on X
  • Israel@f1tym1
    Disclosure

    FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise https://ift.tt/ILJmRjq Other incident responders have already shared insights about threat actor activities within the network once a device has been compromised; for instance, Sent…

    Post summary

    The post announces the discovery of two FortiNet SSO vulnerabilities that can lead to full system compromise, linking to more information but providing no evidence of active exploitation, patches, or technical details.

    0000043
    996 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---
Appfortinetfortiweb8.0.0--

Explore more