Critical Fortinet Authentication Bypass Flaws Exploited in the Wild, Network Perimeters at Risk + Video

Listen to this Post

Featured Image

Introduction

Fortinet infrastructure has once again become the focal point of global cyber defense concerns. Newly disclosed authentication bypass vulnerabilities are no longer theoretical threats, they are actively exploited in real-world attacks. With firewall and network management systems sitting at the heart of enterprise security, the implications extend far beyond isolated devices. What initially appeared as a routine security advisory has rapidly escalated into an urgent operational crisis for organizations relying on Fortinet platforms.

Summary

The US Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical Fortinet vulnerability, tracked as CVE-2025-59718, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw carries a CVSS score of 9.1 and is closely related to a second vulnerability, CVE-2025-59719, also rated critical. Both issues were disclosed by Fortinet on December 9 and affect multiple products, including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. The vulnerabilities stem from improper verification of cryptographic signatures within FortiCloud SSO, allowing attackers to bypass authentication using crafted SAML messages. When FortiCloud SSO is enabled, unauthenticated threat actors can gain administrative access to affected devices. According to Arctic Wolf, exploitation activity began as early as December 12, only days after disclosure. The attacks originated from infrastructure hosted in Germany, the United States, and parts of Asia, targeting primarily administrator accounts on FortiGate devices. Once access was achieved, attackers exported full device configurations, including hashed credentials and sensitive network data. Although FortiCloud SSO is disabled by default, it is automatically enabled when devices are registered through FortiCare unless administrators manually disable the option. This design choice significantly expanded the attack surface. CISA warned that the vulnerability poses a serious risk to federal agencies, mandating remediation by December 23. Fortinet has released patches across affected product lines, while recommending temporary mitigations such as disabling FortiCloud SSO or restricting administrative access. Security experts warn that stolen configuration files may enable future attacks, lateral movement, and long-term persistence within compromised environments.

What Undercode Say:

This incident highlights a recurring structural weakness in enterprise security products, not just a single vendor misstep. Authentication bypass vulnerabilities targeting perimeter devices remain one of the most efficient attack vectors because they collapse trust models instantly. Once a firewall or gateway is compromised, segmentation, monitoring, and policy enforcement lose their meaning.

The FortiCloud SSO behavior deserves particular scrutiny. Automatically enabling cloud-based authentication features during device registration introduces silent risk, especially in environments where administrators assume default-secure configurations. This pattern reflects a broader industry trend where usability and rapid deployment quietly override security fundamentals.

The speed of exploitation is equally telling. Three days from disclosure to active attacks confirms that threat actors are operating with pre-built tooling, monitoring vendor advisories in real time. This is not opportunistic hacking, it is industrialized exploitation driven by automation and reconnaissance pipelines.

Exporting configuration files is a strategic move. These files contain network topology, interface mappings, VPN settings, and credential material. Even hashed credentials are valuable, as offline cracking remains trivial against weak or reused passwords. More importantly, configuration intelligence enables future zero-auth attacks if management interfaces remain exposed.

Another critical issue is exposure management. Many organizations focus heavily on patch scheduling while leaving administrative interfaces publicly reachable. As highlighted by security leaders, patching delays matter less than reducing attack surface. Internet-facing management portals continue to be a systemic failure point across enterprises.

This campaign also reinforces why firewall devices are premium targets. Control over traffic routing, VPN access, and policy enforcement allows attackers to establish durable footholds without deploying malware. Persistence can be achieved through policy changes, rogue admin accounts, or trusted VPN tunnels that blend into legitimate traffic.

From a defensive perspective, incident response should assume credential compromise the moment suspicious SSO activity is detected. Waiting for confirmation risks irreversible damage. Credential resets, configuration audits, and forensic review must be immediate, not scheduled.

Ultimately, this is not just a Fortinet problem. It is a warning about how quickly trust boundaries collapse when authentication logic fails. Organizations that treat perimeter devices as static infrastructure rather than high-risk assets will continue to face the same crisis, vendor after vendor.

Fact Checker Results

✅ The vulnerabilities CVE-2025-59718 and CVE-2025-59719 are confirmed critical with active exploitation.
✅ CISA officially added CVE-2025-59718 to the KEV catalog with mandatory remediation timelines.
❌ Claims that hashed credentials are harmless are inaccurate, as offline cracking remains a real threat.

Prediction

🔮 More firewall and VPN vendors will face similar SAML and SSO-related vulnerabilities as cloud-auth integrations expand.
🔮 Regulatory pressure on rapid patching and exposure reduction will intensify for perimeter security products.
🔮 Attackers will increasingly prioritize configuration theft over malware deployment for stealth persistence.

▶️ Related Video (82% Match):

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.discord.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon