Skip to content
AL25-019 - Vulnerabilities impacting Fortinet products

AL25-019 - Vulnerabilities impacting Fortinet products

Cyber.Gc.Ca December 16, 2025

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

The Cyber Centre is aware of critical FortiCloud SSO Login Authentication Bypass vulnerabilities Footnote 1 affecting Fortinet products with this login feature enabled. Following the vendor advisory, the Cyber Centre issued AV25-821 Footnote 2 on December 9, 2025.

CVE-2025-59718 Footnote 3 and CVE-2025-59719 Footnote 4 allow an improper verification of cryptographic signature vulnerability (CWE-347) Footnote 5 which may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

The Cyber Centre recommends that organizations patch their Fortinet products to the following versions:

If patching is not possible at this time, the Cyber Centre strongly recommends that organizations follow Fortinet customer guidance for mitigation advice Footnote 1 , which involves turning off the FortiCloud login feature (if enabled) temporarily until upgrading to a non-affected version.

In addition, the Cyber Centre also strongly recommends that organizations review and implement the Cyber Centre’s Top 10 IT Security Actions with an emphasis on the following topics Footnote 6 .

Should activity matching the content of this alert is discovered, recipients are encouraged to report via My Cyber Portal , or email @cyber.gc.ca .

Extracted Entities

Companies (1)

Domains (1)

Platforms (2)