Fortinet has released security updates to address critical vulnerabilities affecting their FortiOS, FortiWeb, FortiProxy and FortiSwitchManager products. Users and administrators of affected product versions are advised to update to the latest version immediately.
Fortinet has released security updates to address critical vulnerabilities (CVE-2025-59718 and CVE-2025-59719) affecting FortiOS, FortiProxy, FortiSwitchManager and FortiWeb. Both vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.0) score of 9.8 out of 10.
Successful exploitation of the vulnerabilities could lead to the following:
CVE-2025-59718: This vulnerability involves improper verification of cryptographic signatures in versions of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.
CVE-2025-59719: This vulnerability involves improper verification of cryptographic signatures in Fortinet FortiWeb, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.
The vulnerabilities affect the following product versions:
Users and administrators of affected products are advised to update the affected products to the latest version immediately.
If patching is not immediately possible, administrators may consider turning off the FortiCloud login feature (if enabled) temporarily until upgrading to a non-affected version. To turn off FortiCloud login, go to System -> Settings -> Switch “Allow administrative login using FortiCloud SSO” to Off. Alternatively, type the following command in the CLI:
set admin-forticloud-sso-login disable
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
