Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Updated on 16 Dec 2025 Category: Business • Author: Scoopliner Editorial Team
हिंदी में सुनें

Listen to this article in Hindi

गति:

Threat actors are actively exploiting recently disclosed vulnerabilities in Fortinet FortiGate devices to bypass SAML SSO authentication. Patches are available.


Fortinet FortiGate devices are currently under attack, with malicious actors exploiting two recently revealed security vulnerabilities. These flaws allow attackers to bypass SAML single sign-on (SSO) authentication.

Cybersecurity firm Arctic Wolf reported observing active intrusions on December 12, 2025, involving unauthorized SSO logins on FortiGate appliances. The attacks leverage CVE-2025-59718 and CVE-2025-59719, both carrying a critical CVSS score of 9.8. Fortinet released patches last week for FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager to address these issues.

According to Arctic Wolf Labs, the vulnerabilities enable unauthenticated bypass of SSO login authentication through specially crafted SAML messages, but only if the FortiCloud SSO feature is enabled on the affected devices. While FortiCloud SSO is disabled by default, it is automatically activated during FortiCare registration unless administrators manually disable the "Allow administrative login using FortiCloud SSO" setting on the registration page.

Arctic Wolf's investigation revealed that the malicious SSO logins against the "admin" account originated from IP addresses associated with hosting providers including The Constant Company llc, Bl Networks, and Kaopu Cloud Hk Limited. After gaining access, the attackers exported device configurations through the GUI to the same IP addresses.

Given the ongoing exploitation, organizations are urged to apply the available patches immediately. As a precaution, disabling FortiCloud SSO until the instances are updated to the latest version is recommended. Limiting access to the management interfaces of firewalls and VPNs to trusted internal users is also crucial.

Arctic Wolf also noted that even though credentials are typically hashed in network appliance configurations, attackers are known to crack these hashes offline, particularly if the credentials are weak and susceptible to dictionary attacks. Fortinet customers who identify indicators of compromise (IoCs) consistent with this campaign should assume their systems have been compromised and reset the hashed firewall credentials stored in the exfiltrated configurations.

Source: The Hacker News   •   16 Dec 2025

Related Articles

Ola Electric Founder to Release Rs 260 Crore in Pledged Shares, Reduce Debt
Ola Electric Founder to Release Rs 260 Crore in Pledged Shares, Reduce Debt

Ola Electric founder Bhavish Aggarwal has released Rs 260 crore in pledged shares by selling a portion of his stake, reducing debt …

Source: The Economic Times | 16 Dec 2025
US labour market stumbles in November: Unemployment rate climbs to 4.6% despite addition of 64,000 jobs; highest since 2021
US labour market stumbles in November: Unemployment rate climbs to 4.6% despite addition of 64,000 jobs; highest since 2021

US job creation slowed in November, with unemployment hitting 4.6%, the highest since 2021. 64,000 jobs were added amid economic uncertainty.

Source: Times of India | 16 Dec 2025
Brent Crude Drops Below $60 Amid Ukraine Peace Talk Hopes
Brent Crude Drops Below $60 Amid Ukraine Peace Talk Hopes

Brent crude oil prices dipped below $60 a barrel as optimism surrounding potential Ukraine peace talks increased, impacting global oil supply dynamics.

Zepto Reportedly Plans to File for $500 Million India IPO Next Week
Zepto Reportedly Plans to File for $500 Million India IPO Next Week

Zepto is reportedly preparing to file for a $500 million IPO in India amid rising competition in the quick-commerce grocery delivery market.

Source: The Economic Times | 16 Dec 2025
The Rs 1.6 lakh crore trader: How a Gurgaon-based high-frequency firm quietly dominated India’s intraday market in 2025
The Rs 1.6 lakh crore trader: How a Gurgaon-based high-frequency firm quietly dominated India’s intraday market in 2025

Gurgaon-based Graviton Research executed Rs 1.6 lakh crore in intraday trades in 2025, becoming a dominant force in the Indian market.

Source: Moneycontrol | 16 Dec 2025
Morgan Stanley predicts 16-20% telecom tariff jump in Q1 FY27
Morgan Stanley predicts 16-20% telecom tariff jump in Q1 FY27

Morgan Stanley projects a 16-20% increase in telecom tariffs for 4G/5G plans in the first quarter of fiscal year 2027, marking the …

Source: The Economic Times | 16 Dec 2025
← Back to Home

QR Code Generator