Fortinet FortiOS Authentication Bypass Exploited Days After Patch Release

Listen to this Post

Featured Image

A Rapid Escalation From Disclosure to Active Exploitation

Critical security flaws in Fortinet products moved from disclosure to real-world exploitation in a matter of days, highlighting once again how narrow the defensive window has become for enterprise infrastructure. Arctic Wolf has confirmed that threat actors are actively exploiting two high-severity vulnerabilities, CVE-2025-59718 and CVE-2025-59719, shortly after Fortinet released official patches. With a CVSS score of 9.1, these flaws expose organizations running affected Fortinet systems to immediate and serious risk, especially when FortiCloud Single Sign-On is enabled.

the Original Incident and Technical Findings

Fortinet recently addressed a total of 18 vulnerabilities across its product ecosystem, including FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. Among them, CVE-2025-59718 and CVE-2025-59719 stand out due to their critical nature and exploitation potential. Both vulnerabilities stem from improper verification of cryptographic signatures, a class of flaws that often leads to authentication bypass scenarios.

The vulnerabilities allow an unauthenticated attacker to bypass FortiCloud SSO authentication by sending a specially crafted SAML message. When successful, the attacker can log in as an administrative user without valid credentials. Although FortiCloud SSO is disabled by default in factory settings, it is automatically enabled during FortiCare registration unless administrators explicitly disable the option allowing administrative login via FortiCloud SSO. This behavior significantly increases exposure, particularly in environments where devices were registered quickly or without a full security review.

Fortinet advised customers to disable FortiCloud SSO administrative login as a temporary mitigation until systems can be upgraded to fixed versions. A wide range of FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb versions are affected, with patches released across multiple branches. Older versions such as FortiOS 6.4 and some FortiWeb releases were not impacted.

The vulnerabilities were internally discovered by Fortinet’s Product Security team, but exploitation in the wild followed rapidly. Arctic Wolf observed active attacks beginning on December 12, just three days after Fortinet published its advisory. These attacks involved malicious SSO authentication attempts against FortiGate appliances, primarily targeting administrative accounts hosted across several infrastructure providers.

Once access was obtained, attackers used the FortiGate graphical interface to export device configuration files. These files contain sensitive information, including hashed credentials, which can be cracked offline. This step dramatically increases the blast radius of the compromise, as recovered credentials may be reused across networks or leveraged for lateral movement. Arctic Wolf confirmed that the malicious activity originated from a limited set of IP addresses and stated that detection mechanisms are in place to alert affected customers.

Administrators have been urged to review logs, reset credentials, restrict management access to trusted networks, and apply patches immediately. Fortinet continues to recommend disabling FortiCloud SSO administrative access wherever it is not strictly required.

What Undercode Say:

The most alarming aspect of this incident is not the vulnerability itself, but the speed at which attackers operationalized it. Three days from patch release to confirmed exploitation signals a mature and highly responsive threat ecosystem. This is no longer a scenario where attackers need weeks to reverse engineer patches. Automated diffing, rapid exploit development, and shared tooling have compressed timelines to the point where delay equals compromise.

Improper cryptographic signature verification remains a recurring theme in enterprise security failures. SAML-based authentication flows are complex, and any weakness in validation logic can turn a trust mechanism into an attack vector. In this case, FortiCloud SSO became the weakest link, not because it was insecure by design, but because of how easily it could be enabled during routine device registration.

Another critical insight lies in attacker behavior post-compromise. The immediate export of configuration files shows intent beyond simple access. Configuration data is intelligence gold. It reveals network topology, VPN settings, user structures, and encrypted credentials. Even if hashes are strong, attackers can afford time, and cracked credentials often unlock other systems far beyond the firewall itself.

This incident also reinforces a long-standing operational problem. Security teams often treat “optional” features as low risk, especially when they are disabled by default. However, auto-enablement during onboarding workflows creates a silent exposure gap. Organizations must assume that any feature capable of authenticating administrators is part of the attack surface, regardless of default settings.

From a defensive perspective, patching alone is no longer sufficient. Visibility into authentication logs, strict management plane access controls, and proactive configuration audits are now mandatory. Vendors will continue to ship patches, but attackers will continue to exploit the human and procedural delays that follow.

Fact Checker Results

✅ Fortinet confirmed both CVE-2025-59718 and CVE-2025-59719 as critical authentication bypass vulnerabilities.
✅ Arctic Wolf independently verified active exploitation within days of patch release.
❌ No evidence suggests the flaws affect FortiOS 6.4 or unsupported FortiWeb branches.

Prediction

📊 Exploitation of edge security appliances will accelerate as attackers prioritize identity and management plane weaknesses.
📊 Vendors will face increased pressure to redesign onboarding workflows that silently enable high-risk features.
📊 Organizations that fail to restrict firewall administrative access will remain prime targets for rapid, automated attacks.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon