Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Fortinet vulnerabilities prompt pre-holiday warnings | Computer Weekly

By Computer Weekly by By Computer Weekly
December 19, 2025
Home Uncategorized
Share on FacebookShare on Twitter


Two recently disclosed vulnerabilities discovered in Fortinet’s product portfolio have prompted a pre-holiday warning for defenders after being added to the Known Exploited Vulnerabilities (KEV) catalogue run by the US’ national cyber agency this week.

The two flaws, tracked as CVE-2025-59718 and CVE-2025-59719, enable a threat actor to bypass FortiCloud single sign-on (SSO) authentication via a maliciously crafted security assertion markup language (SAML) message. According to Fortinet, they are present in multiple versions of FortiOS, FortiWeb, FortiProxy and FortiSwitchManager.

It should be noted that while the vulnerable feature is not enabled by default in factory settings, it does activate automatically if and when a device is registered to the FortiCare tech service via the GUI unless the customer admin has explicitly opted out of this.

In a statement, the US Cybersecurity and Infrastructure Security Agency (CISA) said: “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.”

Initially reported by Fortinet on 9 December, multiple third parties are now reporting exploitation activity in progress against CVE-2025-59718 and CVE-2025-59719.

According to Rapid7 analysts – who have been trapping multiple exploit attempts against its honeypots after a proof-of-concept exploit was posted to GitHub, many of the observed attacks have seen attackers authenticate as the admin user and immediately download the target’s system configuration file – these can often hold hashed credentials.

“As a result, any organisation with indicators of compromise [IOCs] must assume credential exposure and respond accordingly. A vendor patch is available, and organisations can also take immediate defensive action by disabling FortiCloud SSO administrative login while remediation efforts are underway,” said the Rapid7 team.

Arctic Wolf researchers said that besides applying the available updates from Fortinet, organisations finding that they are affected should reset their firewall credentials as a precaution, on the basis that they may have been compromised and exfiltrated, and limit access to firewall and virtual private network (VPN) appliances to trusted internal users.

As its products are deeply embedded in many networks Fortinet is frequently targeted by threat actors as an initial access point to their victims’ wider IT environments, so further attempts against the latest pair of flaws are considered highly likely.

Christmas presents

Besides the Fortinet authentication bypass issues, CISA has added a few more high-profile flaws to the KEV catalogue in the run-up to the festive break.

These include CVE-2025-69374, an embedded malicious code vulnerability that has arisen in ASUS Live Update after unauthorised modifications were made in a supply chain cyber attack.

Multiple Cisco products, including AsyncOS software, Cisco Secure Email Gateway and Secure Email, and Web Manager appliances are at risk from an input validation vulnerability, tracked as CVE-2025-20393, via which a threat actor may be able to execute arbitrary commands with root privileges.

Finally, SonicWall users should address CVE-2025-40602, a missing authorisation flaw enabling privilege escalation on the appliance management console of SMA1000 series secure access gateways.

At the time of writing, none of the above-listed vulnerabilities have been observed being used in ransomware attacks.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Cambium Networks Announces Compliance with Minimum Bid Price Rule and Appointment of Interim Chief Financial Officer

Cambium Networks Announces Compliance with Minimum Bid Price Rule and Appointment of Interim Chief Financial Officer

Recommended.

Round Room Celebrates Teachers Nationwide Through Employee-Powered Teachers Rock Initiative

Round Room Celebrates Teachers Nationwide Through Employee-Powered Teachers Rock Initiative

April 22, 2026
Stocks making the biggest moves midday: Dell, Arrowhead Pharmaceuticals, Urban Outfitters & more

Stocks making the biggest moves midday: Dell, Arrowhead Pharmaceuticals, Urban Outfitters & more

November 26, 2025

Trending.

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

April 10, 2025
Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

April 29, 2026
Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio