New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Critical vulnerabilities in multiple Fortinet products – FortiCloud SSO Login Authentication Bypass

Release date
10 December 2025
Alert rating
Critical

Description

Critical vulnerabilities in Multiple Fortinet Products – FortiCloud SSO Login Authentication Bypass CVE-2025-59718 & CVE-2025-59719. ASD’s ACSC recommends organisations update affected products to the latest versions and follow the advice detailed in the Fortinet Advisory.

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This alert has been written primarily for, but is not limited to, business and government.

This alert is intended for a technical audience.

Background

Fortinet has identified multiple critical vulnerabilities in a number of Fortinet Products:

  • CVE-2025-59718: This vulnerability involves improper verification of cryptographic signatures in versions of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.
  • CVE-2025-59719: This vulnerability involves improper verification of cryptographic signatures in Fortinet FortiWeb, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.

ASD’s ACSC recommends that organisations take immediate action to mitigate affected products, apply the latest patches and investigate for potential compromise.

The vulnerabilities impact the following Fortinet Products:

  • FortiOS
    • 7.0.0 through 7.0.17
    • 7.2.0 through 7.2.11
    • 7.4.0 through 7.4.8
    • 7.6.0 through 7.6.3
  • FortiProxy
    • 7.0.0 through 7.0.21
    • 7.2.0 through 7.2.14
    • 7.4.0 through 7.4.10
    • 7.6.0 through 7.6.3
  • FortiSwitchManager
    • 7.0.0 through 7.0.5
    • 7.2.0 through 7.2.6
  • FortiWeb
    • 7.4.0 through 7.4.9
    • 7.6.0 through 7.6.4
    • 8.0.0

Mitigation advice

Australian organisations should review their networks for use of vulnerable versions of the Fortinet Products, and consult the Fortinet Advisory for mitigation advice and patching.

Mitigation may include disabling FortiCloud login (if enabled) until the latest patches are applied.

Organisations should also investigate for any unauthorised access or compromise of affected products.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Protect your assets with Predictive

TisaAssist bot
🤖 Hello, how can I assist you today?
I can help you with:
✅ Answer questions related to the website.
✅ Help you understand things you don't know.
❓ What's Tisalabs
💻 What's IoT
🔒 Why sensor data must be protected?