Fortinet released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could let attackers bypass FortiCloud SSO authentication.
Threat actors can exploit the security flaws CVE-2025-59718 and CVE-2025-59719 by taking advantage of weaknesses in cryptographic signature verification in affected products using a malicious SAML message.
By infosecbulletin
/ Saturday , September 19 2026
Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
By infosecbulletin
/ Friday , September 18 2026
Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and one of three data-hosting zones in the...
Read More
By infosecbulletin
/ Friday , September 18 2026
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
By infosecbulletin
/ Thursday , September 17 2026
Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
By infosecbulletin
/ Thursday , September 17 2026
GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
By infosecbulletin
/ Tuesday , September 15 2026
Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
By infosecbulletin
/ Monday , September 14 2026
Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
By infosecbulletin
/ Saturday , September 12 2026
German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
By infosecbulletin
/ Friday , September 11 2026
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Fortinet stated today that the vulnerable FortiCloud feature isn’t enabled by default if the device isn’t registered with FortiCare.
“Please note that the FortiCloud SSO login feature is not enabled in default factory settings,” Fortinet said. “However, when an administrator registers the device to FortiCare from the device’s GUI, unless the administrator disables the toggle switch ‘Allow administrative login using FortiCloud SSO’ in the registration page, FortiCloud SSO login is enabled upon registration.”
Admins should temporarily disable the FortiCloud login feature until they upgrade to a secure version to protect against attacks exploiting vulnerabilities.
To disable FortiCloud login, navigate to System -> Settings and switch “Allow administrative login using FortiCloud SSO” to Off. Alternatively, you can run the following command from the command-line interface:

The company has fixed another security flaw that let attackers change passwords without permission, as well as another issue allowing password hashes to be used for authentication.

In February, Fortinet revealed that the Chinese Volt Typhoon hacking group infiltrated a Dutch Ministry of Defence network with Coathanger RAT malware, exploiting two FortiOS SSL VPN vulnerabilities (CVE-2023-27997 and CVE-2022-42475).
In August, Fortinet fixed a command injection vulnerability (CVE-2025-25256) in FortiSIEM, just after GreyNoise reported a rise in brute-force attacks on Fortinet SSL VPNs.