Complex Mathematics

Fortinet products hit by further security flaws – giving hackers access to systems and more



  • Two critical SAML‑signature flaws (CVE‑2025‑59718/59719) let attackers bypass SSO across multiple Fortinet products
  • Exploitation began December 12, with intruders pulling config files that expose network layouts and hashed passwords
  • Fortinet urges disabling FortiCloud login and upgrading immediately to the patched versions listed

Two new critical vulnerabilities have been discovered in Fortinet products, and since they are being actively abused in the wild, both the company and security researchers are urging users to upgrade to the newest version as soon as possible.

In a newly released security advisory (via BleepingComputer), Fortinet said it discovered an SSO authentication bypass bug in FortiOS, FortiProxy, and FortiSwitchManager, caused by improper verification of cryptographic signatures in SAML messages.





Source link