Exploited CVE-2025-59718 Compromises FortiGate Firewalls Despite Patches

Exploited CVE-2025-59718 Compromises FortiGate Firewalls Despite Patches

First seen 25 Jan 2026, 12:39 UTC Feeds2.FeedburnerHelpnetsecurity 24.3

Article Content

Browse articles
ThreatCluster

FortiGate firewalls are being compromised through CVE-2025-59718, a critical authentication bypass flaw. Despite Fortinet's claims that the vulnerability was patched in FortiOS versions 7.6.4 and above, reports indicate that attackers are still able to exploit the flaw in newer releases. This issue was first exploited in December 2025.