By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Fortinet vulnerabilities prompt pre-holiday warnings | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Fortinet vulnerabilities prompt pre-holiday warnings | Computer Weekly
News

Fortinet vulnerabilities prompt pre-holiday warnings | Computer Weekly

News Room
Last updated: 2025/12/18 at 10:49 AM
News Room Published 18 December 2025
Share
Fortinet vulnerabilities prompt pre-holiday warnings | Computer Weekly
SHARE

Two recently disclosed vulnerabilities discovered in Fortinet’s product portfolio have prompted a pre-holiday warning for defenders after being added to the Known Exploited Vulnerabilities (KEV) catalogue run by the US’ national cyber agency this week.

The two flaws, tracked as CVE-2025-59718 and CVE-2025-59719, enable a threat actor to bypass FortiCloud single sign-on (SSO) authentication via a maliciously crafted security assertion markup language (SAML) message. According to Fortinet, they are present in multiple versions of FortiOS, FortiWeb, FortiProxy and FortiSwitchManager.

It should be noted that while the vulnerable feature is not enabled by default in factory settings, it does activate automatically if and when a device is registered to the FortiCare tech service via the GUI unless the customer admin has explicitly opted out of this.

In a statement, the US Cybersecurity and Infrastructure Security Agency (CISA) said: “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”

Initially reported by Fortinet on 9 December, multiple third parties are now reporting exploitation activity in progress against CVE-2025-59718 and CVE-2025-59719.

According to Rapid7 analysts – who have been trapping multiple exploit attempts against its honeypots after a proof-of-concept exploit was posted to GitHub, many of the observed attacks have seen attackers authenticate as the admin user and immediately download the target’s system configuration file – these can often hold hashed credentials.

“As a result, any organisation with indicators of compromise [IOCs] must assume credential exposure and respond accordingly. A vendor patch is available, and organisations can also take immediate defensive action by disabling FortiCloud SSO administrative login while remediation efforts are underway,” said the Rapid7 team.

Arctic Wolf researchers said that besides applying the available updates from Fortinet, organisations finding that they are affected should reset their firewall credentials as a precaution, on the basis that they may have been compromised and exfiltrated, and limit access to firewall and virtual private network (VPN) appliances to trusted internal users.

As its products are deeply embedded in many networks Fortinet is frequently targeted by threat actors as an initial access point to their victims’ wider IT environments, so further attempts against the latest pair of flaws are considered highly likely.

Christmas presents

Besides the Fortinet authentication bypass issues, CISA has added a few more high-profile flaws to the KEV catalogue in the run-up to the festive break.

These include CVE-2025-69374, an embedded malicious code vulnerability that has arisen in ASUS Live Update after unauthorised modifications were made in a supply chain cyber attack.

Multiple Cisco products, including AsyncOS software, Cisco Secure Email Gateway and Secure Email, and Web Manager appliances are at risk from an input validation vulnerability, tracked as CVE-2025-20393, via which a threat actor may be able to execute arbitrary commands with root privileges.

Finally, SonicWall users should address CVE-2025-40602, a missing authorisation flaw enabling privilege escalation on the appliance management console of SMA1000 series secure access gateways.

At the time of writing, none of the above-listed vulnerabilities have been observed being used in ransomware attacks.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Fire Stick ‘exodus’ as users quit popular device over illegal streaming changes Fire Stick ‘exodus’ as users quit popular device over illegal streaming changes
Next Article Thunderbird Expanding Microsoft Exchange & Protocol Support For 2026 Thunderbird Expanding Microsoft Exchange & Protocol Support For 2026
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Use Edge Light for Better Video Calls in macOS
Use Edge Light for Better Video Calls in macOS
News
Why a high-profile discrimination case against Kuda was dismissed
Why a high-profile discrimination case against Kuda was dismissed
Computing
You Can (Still) Stream All the James Bond Films in Order. Here’s How to Watch.
You Can (Still) Stream All the James Bond Films in Order. Here’s How to Watch.
News
Best travel backpacks in 2026 for laptops, tech and more
Best travel backpacks in 2026 for laptops, tech and more
Gadget

You Might also Like

Use Edge Light for Better Video Calls in macOS
News

Use Edge Light for Better Video Calls in macOS

3 Min Read
You Can (Still) Stream All the James Bond Films in Order. Here’s How to Watch.
News

You Can (Still) Stream All the James Bond Films in Order. Here’s How to Watch.

16 Min Read
Android 16 QPR3 will tell you if apps use your location
News

Android 16 QPR3 will tell you if apps use your location

2 Min Read
AI Is Going To Make Your Next Computer Cost A Lot More, And It’s Pretty Clear Why – BGR
News

AI Is Going To Make Your Next Computer Cost A Lot More, And It’s Pretty Clear Why – BGR

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?