VulnerAlert



CLOUD
FORTINET
16-12-2025 08:16
Tags
#hacker
#exploit
#critical
#web
#using
#html
#fortigate
#admin
#fortinet
#cloud
#/.net(.*)core(.*).net(.*)5/iU
#.net core .net 5
#/.net(.*)core/iU
#.net core
#affected
#authenticated
#bypass
#threat
#security
#patch
#pass
#malicious
#intrusion
#flaw
#critic
#allow
#attack
#affect
Descripción
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass Threat actors have begun to exploit two newly disclosed security flaws in Fortinet devices, less than a week after public disclosure. Cybersecurity company Arctic Wolf said it observed active intrusions involving malicious single sign-on (SSO) logins on appliances December 12, 2025. The attacks critical authentication bypasses (CVE-2025-59718 and CVE-2025-59719, CVSS scores: 9.8). Patches for the were released by last FortiOS, FortiWeb, FortiProxy, FortiSwitchManager. "These vulnerabilities allow unauthenticated bypass of login via crafted messages, if FortiCloud feature is enabled affected devices," Labs new bulletin. It's worth noting that while disabled default, automatically during FortiCare registration unless administrators explicitly turn off using "Allow administrative SS... https://thehackernews.com/2025/12/fortinet-fortigate-under-active-attack.html
CVE-2025-59718
CVE-2025-59719
Link externo
Ver detalles

Fuente
https://thehackernews.com/2025/12/fortinet-fortigate-under-active-attack.html
Resultados similares
Coincidentes en almenos en 50% de los tags
16-12-2025 CVE-2025-14780
A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affe...
Ver información
16-12-2025 CVE-2025-66407
Weblate is a web based localization tool. The Create Component functionality in Weblate allows ...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por