• Our channels:
  • Cyber Risk
  • Chief IT
  • Australian Security
  • Asia Pacific
  • Southeast Asia
  • Space
  • Smart Cities
  • Drones & Robotics
  • Video Systems
  • Podcast
  • MySec.TV
  • Best in Tech
  • MySmartTech
Australian Cyber Security Magazine
Navigate
  • Australian Cyber Security Magazine
  • News
    • Featured
    • Editor’s Desk
    • Skills & Training
    • Governance, Risk & Compliance
    • Hacking & Penetration Testing
    • Information Security
    • Strategy & Architecture
    • MySecurity TV
    • Cyber Security Weekly Podcast
  • Contributors
  • Magazines
  • Events
  • RESOURCES
  • TRAINING
  • SHOP
  • Advertise
  • Subscribe

Critical vulnerabilities in multiple Fortinet products – FortiCloud SSO Login Authentication Bypass

0
By ACSM_Accro on December 11, 2025 Cyber Security, Featured, Governance, Risk & Compliance, Vulnerabilities
The Australian Cyber Security Centre has issued a technical alert advising business and government organisations to take immediate action following the discovery of multiple critical vulnerabilities affecting several Fortinet products.
The flaws, disclosed by Fortinet, relate to improper verification of cryptographic signatures and could allow unauthenticated attackers to bypass FortiCloud single sign-on authentication using crafted SAML response messages.
Two vulnerabilities have been identified. CVE-2025-59718 affects FortiOS, FortiProxy and FortiSwitchManager, while CVE-2025-59719 affects FortiWeb. Both expose organisations to authentication bypass risks, and the ACSC recommends urgent mitigation, including patching and investigations for signs of compromise.
The vulnerabilities impact the following product versions:
FortiOS
  • 7.0.0 to 7.0.17
  • 7.2.0 to 7.2.11
  • 7.4.0 to 7.4.8
  • 7.6.0 to 7.6.3
FortiProxy
  • 7.0.0 to 7.0.21
  • 7.2.0 to 7.2.14
  • 7.4.0 to 7.4.10
  • 7.6.0 to 7.6.3
FortiSwitchManager
  • 7.0.0 to 7.0.5
  • 7.2.0 to 7.2.6
FortiWeb
  • 7.4.0 to 7.4.9
  • 7.6.0 to 7.6.4
  • 8.0.0
Australian organisations are recommended to review their environments, identify affected versions and follow Fortinet’s mitigation guidance. Recommended actions include applying the latest patches as soon as possible and disabling FortiCloud login, where enabled, until updates are deployed. Organisations should also investigate for any signs of unauthorised access or attempted compromise.
Assistance is available for organisations that have been impacted or require guidance. The ACSC can be contacted via 1300 CYBER1 (1300 292 371). Full details of the alert can be found on cyber.gov.au, and incidents of cybercrime can be reported through ReportCyber.
Share. Twitter Facebook Pinterest LinkedIn Tumblr Email

Related Posts

  • APP-ACSM | Featured | Information Security | December 10, 2025

    Final Patch Tuesday of 2025 with Zero-Day

  • APP-ACSM | Editor's Desk | Featured | Governance, Risk & Compliance | December 10, 2025

    The Great Australian scroll-back: social media ban in place

  • APP-ACSM | Cyber Security | Featured | Governance, Risk & Compliance | White Papers & Research | December 9, 2025

    Australia experienced highest ransomware rate globally, second highest in ransom payments

ENJOY OUR OTHER CHANNELS

  • The Australian Cyber Security Magazine covers the broad domain of cybersecurity with news, updates and contributed articles from leading security professionals from
    across the world. The Editorial importantly sets the scene for a challenging threat landscape, with continued reports of serious data breaches.

    MySecurity Media Pty Limited
    ABN 54 145 849 056
    A: GPO Box 930 Sydney NSW 2001
    E: promoteme@mysecuritymedia.com
    W: www.mysecuritymedia.com

  • NETWORK

    • Marketplace
    • Community
    • Contributors
    • Lead Publication
    • Promote Your Brand
    • Privacy Policy
  • NEWS

    • Featured
    • Editor’s Desk
    • Skills & Training
    • Governance, Risk & Compliance
    • Hacking & Penetration Testing
    • Information Security
    • Strategy & Architecture
  • DOWNLOAD APP

  • EVENTS
    > Find a Speaker
    > New Arrivals
    > Upcoming Events
    > Past Events
    > Register an Event
  • RESOURCES
    > Reports
    > Whitepapers
    > Research
    > Books
    > COVID 19 Resources
    > Magazines
    > Podcasts
    > MySecurity TV
    > Australia in Space TV
  • PRODUCTS
    > Solution Products
    > Online Store
    > TeePublic Store
    > Promote Your Brand

    TRAINING
    > Courses
    > Webinars – Live
    > Webinars – On Demand
    > Learn Security Platform
  • COMMUNITY
    > Indo-Pacific Space and Earth Network
    > Space and Earth - Partners and Advisory
    > IPRAAC
    > IPSEC
    > Security & Risk Professional Insight Series
    > Women in Security Awards
    > Partners
    > Speakers
    > Providers
    > Promote Your Brand
  • NEWS CHANNELS
    > MySec.TV
    > Australia in Space TV
    > Cyber Security Weekly Podcast
    > Cyber Risk Leaders
    > Chief IT
    > Drones & Robotics
    > Space & Defense
    > Australia in Space
    > Smart Cities Tech
    > Video Systems
    > Asia Pacific Security Magazine
    > ASEAN Technology & Security
    > Australian Cyber Security Magazine
    > Australian Security Magazine

© My Security Media. All Right Reserved 2019.   Privacy Policy | Terms & Conditions | Competition T&Cs