Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
These articles are AI-generated summaries. Please check the original sources for full details.
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
Threat actors are actively exploiting two critical vulnerabilities (CVE-2025-59718 and CVE-2025-59719) in Fortinet FortiGate devices just days after their disclosure on December 12, 2025, with Arctic Wolf observing malicious SSO logins. These flaws allow unauthenticated bypass of SSO login authentication via crafted SAML messages.
Why This Matters
Current network security relies on strong authentication, but complex systems like SAML introduce vulnerabilities if improperly configured or patched. Ideal models assume timely updates; in practice, patching lags, leaving a window for exploitation. This particular campaign targets FortiGate, impacting potentially thousands of organizations, and data exfiltration through configuration exports represents a significant risk, with potential costs reaching millions in incident response and remediation.
Key Insights
- Active Exploitation: Observed malicious SSO logins starting December 12, 2025 (Arctic Wolf).
- SAML Complexity: SAML vulnerabilities often stem from improper message validation and trust relationships.
- CISA Action: CVE-2025-59718 added to CISA’s KEV catalog; FCEB agencies must patch by December 23, 2025.
Practical Applications
- Use Case: Organizations using FortiCloud SSO with FortiGate devices are at immediate risk of unauthorized access and potential data exfiltration.
- Pitfall: Relying on default configurations (like automatic FortiCloud SSO enablement during FortiCare registration) without explicit security review amplifies risk.
References:
Continue reading
Next article
Google to Shut Down Dark Web Monitoring Tool in February 2026
Related Content
CISA Adds Gladinet and CWP Vulnerabilities to KEV Catalog Amid Active Exploitation
CISA has added critical vulnerabilities in Gladinet, CWP, and WordPress plugins to its KEV catalog, emphasizing urgent patching due to active exploitation in the wild.
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
Critical WordPress plugin flaw (CVE-2025-8489, CVSS 9.8) allows unauthenticated admin account creation, with 48,400+ exploit attempts blocked by Wordfence.
Critical 'MongoBleed' Bug Under Attack, Patch Now
A critical memory leak in MongoDB allows unauthenticated attackers to steal credentials and data, with active exploitation confirmed as of January 5, 2026.