{"id":9239,"date":"2025-12-16T10:03:40","date_gmt":"2025-12-16T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/16\/critical-fortigate-devices-sso-vulnerabilities-actively-exploited-in-the-wild\/"},"modified":"2025-12-16T10:03:40","modified_gmt":"2025-12-16T10:03:40","slug":"critical-fortigate-devices-sso-vulnerabilities-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/16\/critical-fortigate-devices-sso-vulnerabilities-actively-exploited-in-the-wild\/","title":{"rendered":"Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild"},"content":{"rendered":"<p>    Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet\u2019s FortiGate appliances and related products.<\/p>\n<p>Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated <a href=\"https:\/\/cybersecuritynews.com\/single-sign-on-solutions\/\" target=\"_blank\" rel=\"noreferrer noopener\">single sign-on (SSO)<\/a> logins via malicious SAML messages, granting attackers administrative access.<\/p>\n<p>Fortinet disclosed the flaws in a PSIRT advisory on December 9, 2025. Arctic Wolf quickly followed with its own security bulletin, urging immediate patching.<\/p>\n<p>The vulnerabilities affect multiple product lines, FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager, when FortiCloud SSO is enabled.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/critical-fortinet-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">FortiCloud SSO<\/a> login remains disabled by default in factory settings. However, it activates automatically during device registration via FortiCare GUI unless administrators explicitly disable the \u201cAllow administrative login using FortiCloud SSO\u201d option. This common oversight exposes internet-facing devices to remote exploitation.<\/p>\n<p>Once enabled, attackers craft SAML assertions to bypass authentication entirely. Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/cve-2025-59718-and-cve-2025-59719\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reports<\/a> intrusions originating from a limited set of IP addresses assigned to providers such as The Constant Company LLC and Kaopu Cloud HK Limited. These actors primarily target the default \u201cadmin\u201d account.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>IOC<\/th>\n<th>Hosting Provider<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>45.32.153[.]218<\/td>\n<td>The Constant Company LLC<\/td>\n<\/tr>\n<tr>\n<td>167.179.76[.]111<\/td>\n<td>The Constant Company LLC<\/td>\n<\/tr>\n<tr>\n<td>199.247.7[.]82<\/td>\n<td>The Constant Company LLC<\/td>\n<\/tr>\n<tr>\n<td>45.61.136[.]7<\/td>\n<td>Bl Networks<\/td>\n<\/tr>\n<tr>\n<td>38.54.88[.]203<\/td>\n<td>Kaopu Cloud HK Limited<\/td>\n<\/tr>\n<tr>\n<td>38.54.95[.]226<\/td>\n<td>Kaopu Cloud HK Limited<\/td>\n<\/tr>\n<tr>\n<td>38.60.212[.]97<\/td>\n<td>Kaopu Cloud HK Limited<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>A sample log from a compromised FortiGate shows a successful SSO login:<br \/><code>date=2025-12-12 time=REDACTED ... logid=\"0100032001\" ... user=\"admin\" ui=\"sso(199.247.7[.]82)\" method=\"sso\" srcip=199.247.7[.]82 ... action=\"login\" status=\"success\" ...<\/code><\/p>\n<p>Post-login, attackers exported device configurations via GUI from the same IPs, as evidenced by:<br \/><code>date=2025-12-12 time=REDACTED ... logid=\"0100032095\" ... action=\"download\" ... msg=\"System config file has been downloaded by user admin via GUI(199.247.7[.]82)\"<\/code><\/p>\n<p>Arctic Wolf\u2019s managed detection and response (MDR) platform identifies these patterns and continues alerting affected customers.<\/p>\n<p>Fortinet has <a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-647\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> fixed versions across branches. Products like FortiOS 6.4, FortiWeb 7.0, and FortiWeb 7.2 remain unaffected.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Product<\/th>\n<th>Affected Versions<\/th>\n<th>Fixed Version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>FortiOS 7.6<\/td>\n<td>7.6.0 \u2013 7.6.3<\/td>\n<td>7.6.4+<\/td>\n<\/tr>\n<tr>\n<td>FortiOS 7.4<\/td>\n<td>7.4.0 \u2013 7.4.8<\/td>\n<td>7.4.9+<\/td>\n<\/tr>\n<tr>\n<td>FortiOS 7.2<\/td>\n<td>7.2.0 \u2013 7.2.11<\/td>\n<td>7.2.12+<\/td>\n<\/tr>\n<tr>\n<td>FortiOS 7.0<\/td>\n<td>7.0.0 \u2013 7.0.17<\/td>\n<td>7.0.18+<\/td>\n<\/tr>\n<tr>\n<td>FortiProxy 7.6<\/td>\n<td>7.6.0 \u2013 7.6.3<\/td>\n<td>7.6.4+<\/td>\n<\/tr>\n<tr>\n<td>FortiProxy 7.4<\/td>\n<td>7.4.0 \u2013 7.4.10<\/td>\n<td>7.4.11+<\/td>\n<\/tr>\n<tr>\n<td>FortiProxy 7.2<\/td>\n<td>7.2.0 \u2013 7.2.14<\/td>\n<td>7.2.15+<\/td>\n<\/tr>\n<tr>\n<td>FortiProxy 7.0<\/td>\n<td>7.0.0 \u2013 7.0.21<\/td>\n<td>7.0.22+<\/td>\n<\/tr>\n<tr>\n<td>FortiSwitchManager 7.2<\/td>\n<td>7.2.0 \u2013 7.2.6<\/td>\n<td>7.2.7+<\/td>\n<\/tr>\n<tr>\n<td>FortiSwitchManager 7.0<\/td>\n<td>7.0.0 \u2013 7.0.5<\/td>\n<td>7.0.6+<\/td>\n<\/tr>\n<tr>\n<td>FortiWeb 8.0<\/td>\n<td>8.0.0<\/td>\n<td>8.0.1+<\/td>\n<\/tr>\n<tr>\n<td>FortiWeb 7.6<\/td>\n<td>7.6.0 \u2013 7.6.4<\/td>\n<td>7.6.5+<\/td>\n<\/tr>\n<tr>\n<td>FortiWeb 7.4<\/td>\n<td>7.4.0 \u2013 7.4.9<\/td>\n<td>7.4.10+<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>If malicious logs appear, reset all firewall credentials immediately. Even hashed passwords in exported configs remain vulnerable to offline dictionary attacks on weak secrets.<\/p>\n<p>Restrict management interfaces to trusted internal networks only. Arctic Wolf has tracked <a href=\"https:\/\/cybersecuritynews.com\/new-attack-targeting-japanese-companies\/\" target=\"_blank\" rel=\"noreferrer noopener\">repeated campaigns<\/a> hitting Fortinet and similar appliances, often via exposed search engines.<\/p>\n<p>As a temporary workaround, disable FortiCloud SSO: Navigate to System &gt; Settings and toggle \u201cAllow administrative login using FortiCloud SSO\u201d to Off, or run CLI:<\/p>\n<pre class=\"wp-block-preformatted\">text<code>config system global\nset admin-forticloud-sso-login disable\nend\n<\/code><\/pre>\n<p>Organizations should prioritize upgrades amid rising firewall targeting. Arctic Wolf emphasizes vigilance, with ongoing detections in place.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fortigate-devices-sso-vulnerabilities\/\">Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fortigate-devices-sso-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet\u2019s FortiGate appliances and related products. Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins via malicious SAML messages, granting attackers administrative access. Fortinet disclosed the flaws in a PSIRT [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2169,124,131,648],"tags":[130],"class_list":["post-9239","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-exploit","category-phishing","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9239"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9239"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9239\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9239"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9239"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9239"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}