Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719 exploited in the wild


A recently disclosed pair of vulnerabilities affecting Fortinet devices—CVE-2025-59718 and CVE-2025-59719—are drawing urgent attention after confirmation of their active exploitation in the wild. The vulnerabilities carry a critical CVSSv3 score and allow an unauthenticated remote attacker to bypass authentication using a crafted SAML message, ultimately gaining administrative access to the device.

Current information indicates that the two CVEs have the same root cause and are differentiated by the products affected: CVE-2025-59719 specifically affects FortiWeb, while CVE-2025-59718 affects FortiOS, FortiProxy, and FortiSwitchManager. While the vulnerable FortiCloud SSO feature is disabled by default in factory settings, it is automatically enabled when a device is registered to FortiCare via the GUI, unless an administrator explicitly opts out.

Read more…
Source: Rapid7


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK MoD says no data leaked to China via drone vulnerability

    August 10, 2026

    Britain’s Ministry of Defence said on Monday that there is no evidence that military data was compromised after a cyber vulnerability was discovered in Royal Navy drones. The issue was identified during routine cybersecurity testing, the ministry said, adding that it continues to conduct security checks across its equipment and systems. Read more… Source:  EUROACTIV Sign up for the ...

  • Top US hedge funds targeted by major vishing campaign

    August 9, 2026

    Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned. BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – ...

  • Ransomware gangs skip the CEO, head straight for the 40-something IT manager

    August 9, 2026

    Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data suggests today’s ransomware crews have ...

  • Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

    August 7, 2026

    Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand ...

  • Swiss government says SharePoint-linked data breach affected hundreds of accounts

    August 7, 2026

    Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation. In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal ...

  • Buggy microcontrollers making up some of the world’s most important servers can be easily backdoored

    August 6, 2026

    Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular enterprise servers. BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide ...