Back to News
Market Impact: 0.35

CVE-2025-59718 and CVE-2025-59719: FortiCloud SSO Login Authentication Bypass

FTNT
Cybersecurity & Data PrivacyTechnology & Innovation

On Dec. 9, 2025 Fortinet disclosed two critical authentication‑bypass vulnerabilities (CVE‑2025‑59718, CVE‑2025‑59719) in FortiOS, FortiWeb, FortiProxy and FortiSwitchManager that allow an unauthenticated actor to bypass FortiCloud SSO via a crafted SAML message if FortiCloud SSO is enabled. Fortinet notes the feature is disabled by factory default but is automatically enabled when a device is registered to FortiCare via the GUI unless administrators manually toggle off “Allow administrative login using FortiCloud SSO”; the vendor and Arctic Wolf advise immediate upgrades to the listed fixed versions across affected releases or, as a temporary mitigation, disabling FortiCloud SSO. There is no known in‑the‑wild exploitation or public PoC yet, but given past targeting of Fortinet products, these flaws represent a high‑risk initial‑access vector for organizations that have the feature enabled.

Analysis

Fortinet on December 9, 2025 disclosed two critical authentication-bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) impacting FortiOS, FortiWeb, FortiProxy and FortiSwitchManager that allow an unauthenticated actor to bypass FortiCloud SSO via a crafted SAML message when the feature is enabled. Fortinet notes FortiCloud SSO is disabled by factory default but is automatically enabled when an administrator registers a device to FortiCare via the GUI unless the "Allow administrative login using FortiCloud SSO" toggle is turned off. Affected release windows and fixed versions are explicitly published: FortiOS 7.6.0–7.6.3 fixed in 7.6.4+, 7.4.0–7.4.8 fixed in 7.4.9+, 7.2.0–7.2.11 fixed in 7.2.12+, 7.0.0–7.0.17 fixed in 7.0.18+; FortiProxy, FortiWeb and FortiSwitchManager have analogous fixed release thresholds and FortiOS 6.4, FortiWeb 7.0 and 7.2 are unaffected. Fortinet and Arctic Wolf advise immediate upgrade to the listed fixed versions or temporarily disabling FortiCloud SSO via System → Settings or the provided CLI. There is no known in-the-wild exploitation and no public proof-of-concept at this time, but the advisory and historical targeting of Fortinet products increase the probability that threat actors will attempt to weaponize these flaws as an initial-access vector. The public guidance, fixed-release availability and a simple temporary mitigation reduce near-term systemic risk, but customer remediation timelines, patch adoption rates and any future PoC/exploitation will be the primary drivers of operational impact. Market signals show a moderately negative sentiment and a modest market-impact score (0.35), implying potential short-term reputational or service-cost headwinds for Fortinet if patching is slow or incidents follow.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.40

Ticker Sentiment

FTNT-0.40

Key Decisions for Investors

  • Monitor Fortinet (FTNT) closely for metrics on customer patch adoption and any reported exploit activity within the next 30–60 days, as slow uptake materially raises operational risk
  • If you have meaningful long exposure to FTNT, consider trimming or hedging near-term position risk until clear evidence of widespread patch deployment or absence of exploitation emerges
  • Avoid initiating new large long positions based solely on this event; re-evaluate on confirmed remediation progress, customer communications and absence of public PoC or breaches
  • Watch for vendor guidance on support costs, contractual remediation obligations or customer churn in upcoming earnings commentary as triggers to reassess valuation and risk premia