Key Takeaways
- Researchers have detected intrusion activity targeting Fortinet FortiGate appliances using malicious single sign-on (SSO) logins.
- The threat activity exploits two critical authentication bypass vulnerabilities in Fortinet products, tracked as CVE-2025-59718 and CVE-2025-59719.
- The vulnerabilities allow an attacker to bypass FortiCloud SSO authentication using a crafted SAML message.
- Users are advised to temporarily disable the FortiCloud login feature on vulnerable versions until upgrades are applied.
- The Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog.
Introduction to the Threat
Researchers at Arctic Wolf have warned of a new threat activity that targets Fortinet FortiGate appliances using malicious single sign-on (SSO) logins. This threat was first discovered on Friday, and it comes about a week after Fortinet disclosed two critical authentication bypass vulnerabilities in multiple products. The vulnerabilities, tracked as CVE-2025-59718 and CVE-2025-59719, were originally discovered by two members of Fortinet’s product security team. These flaws allow an attacker to bypass the FortiCloud SSO authentication using a crafted SAML message if the feature is enabled on the device.
Detection and Investigation
Arctic Wolf originally detected the malicious logins on networks it protects through its managed detection and response service. The company advised its customers of the vulnerabilities in a December 10 bulletin, and since the malicious logins were detected, it has observed tens of intrusions. Researchers are still investigating the incidents and do not know who may be behind the threat activity. They added that the intrusions "appear to be opportunistic in nature" and not targeting specific companies. Arctic Wolf researchers have reached out to Fortinet and provided additional technical details about the threat activity. Another company, Defused, has also detected threat activity, noting that seven different IPs were found exploiting its Fortinet honeypots over the weekend.
Vulnerability Details
The FortiCloud SSO feature is not enabled under factory default settings, but when an administrator registers the device from the graphical user interface, the setting is enabled unless an administrator disables a toggle switch that reads: "Allow administrative login using FortiCloud SSO." This means that many devices may be vulnerable to the threat activity, as the feature is enabled by default in many cases. Fortinet has advised users to temporarily disable the FortiCloud login feature on vulnerable versions until upgrades are applied. This is a critical step in preventing the exploitation of the vulnerabilities, as it will prevent attackers from using the malicious SSO logins to gain access to the devices.
Response and Recommendations
The Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog, highlighting the severity of the threat. Arctic Wolf recommends that users detect malicious activity and reset firewall credentials. Additionally, users should limit firewall management interface access to trusted internal networks. This will help to prevent attackers from exploiting the vulnerabilities and gaining access to the devices. It is also important for users to apply the upgrades provided by Fortinet as soon as possible, in order to patch the vulnerabilities and prevent further exploitation.
Conclusion and Next Steps
In conclusion, the threat activity targeting Fortinet FortiGate appliances using malicious SSO logins is a serious concern that requires immediate attention. Users must take steps to protect their devices, including disabling the FortiCloud login feature, resetting firewall credentials, and limiting access to trusted internal networks. It is also essential to apply the upgrades provided by Fortinet as soon as possible, in order to patch the vulnerabilities and prevent further exploitation. By taking these steps, users can help to prevent the exploitation of the vulnerabilities and protect their devices from the threat activity. As the investigation into the incidents continues, it is likely that more information will become available, and users should stay informed and take additional steps as necessary to protect their devices and networks.


