Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

CISA: Multiple Fortinet Products Exploited In Attacks, Rapid Patching Urged

CRN by CRN
December 16, 2025
Home News
Share on FacebookShare on Twitter


For the second time in the past month, the U.S. cybersecurity agency issued an advisory giving government agencies just a week to remediate an exploited vulnerability in Fortinet products.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging Fortinet customers to prioritize patching for a critical-severity vulnerability, which impacts multiple products from the vendor and has been exploited in cyberattacks.

CISA confirmed in an advisory Tuesday that the vulnerability impacting Fortinet FortiOS, FortiSwitchMaster, FortiProxy and FortiWeb (tracked as CVE-2025-59718) has seen exploitation by threat actors.

[Related: 10 Major Cyberattacks And Data Breaches In 2025 (So Far)]

CRN has reached out to Fortinet for comment.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA wrote in its advisory. The agency said it “strongly urges all organizations” that are affected to prioritize patching activities.

CISA is requiring federal agencies to implement patches for the flaw, which was added to its catalog of vulnerabilities known to have seen exploitation Tuesday, by Dec. 23.

That makes this the second time in the past month that CISA has given government agencies just a week to remediate an exploited Fortinet vulnerability, following the mandate issued Nov. 18 over a FortiWeb vulnerability.

In the case of the critical-severity vulnerability affecting multiple Fortinet products, the flaw was initially disclosed by the cybersecurity vendor Dec. 9.

The vulnerability—which involves improper verification of cryptographic signatures—“may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message, if that feature is enabled on the device,” Fortinet said in its disclosure.

Fortinet recommended that organizations temporarily disable the FortiCloud login feature until fixes are implemented.



Source link

Tags: CyberattacksCybersecuritynetwork securityVulnerabilities
CRN

CRN

Next Post
SK hynix, Nvidia Jointly Developing SDDs For AI Inference: Report

SK hynix, Nvidia Jointly Developing SDDs For AI Inference: Report

Recommended.

Huawei et ses partenaires industriels parviennent à un consensus sur les réseaux de base de l’IA mobile pour promouvoir la monétisation de l’expérience 5G-A

Huawei et ses partenaires industriels parviennent à un consensus sur les réseaux de base de l’IA mobile pour promouvoir la monétisation de l’expérience 5G-A

June 28, 2025
Conexon Connect’s rural fiber internet momentum continues with 13th network completed within five years

Conexon Connect’s rural fiber internet momentum continues with 13th network completed within five years

March 25, 2026

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio