Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    This Week’s Awesome Tech Stories From Around the Web (Through March 14)

    March 14, 2026

    Groov-e Neo Buds Review – Trusted Reviews

    March 14, 2026

    I avoided liquid cooling for years and that was a huge mistake

    March 14, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Tech Gadgets»Fortinet products hit by further security flaws – giving hackers access to systems and more
    Fortinet products hit by further security flaws – giving hackers access to systems and more
    Tech Gadgets

    Fortinet products hit by further security flaws – giving hackers access to systems and more

    The Tech GuyBy The Tech GuyDecember 17, 2025No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement



    • Two critical SAML‑signature flaws (CVE‑2025‑59718/59719) let attackers bypass SSO across multiple Fortinet products
    • Exploitation began December 12, with intruders pulling config files that expose network layouts and hashed passwords
    • Fortinet urges disabling FortiCloud login and upgrading immediately to the patched versions listed

    Two new critical vulnerabilities have been discovered in Fortinet products, and since they are being actively abused in the wild, both the company and security researchers are urging users to upgrade to the newest version as soon as possible.

    Advertisement

    In a newly released security advisory (via BleepingComputer), Fortinet said it discovered an SSO authentication bypass bug in FortiOS, FortiProxy, and FortiSwitchManager, caused by improper verification of cryptographic signatures in SAML messages.

    As a result, a threat actor can submit a maliciously crafted SAML assertion and log in without proper credentials.


    You may like

    Disabling FortiCloud login

    The bug is tracked as CVE-2025-59718, and was given a severity score of 9.8/10 (critical). It affects multiple versions of the products:

    FortiOS 7.6.0 through 7.6.3,
    7.4.0 through 7.4.8,
    7.2.0 through 7.2.1,
    7.0.0 through 7.0.17,
    FortiProxy 7.6.0 through 7.6.3,
    7.4.0 through 7.4.10,
    7.2.0 through 7.2.14,
    7.0.0 through 7.0.21
    FortiSwitchManager 7.2.0 through 7.2.6,
    7.0.0 through 7.0.5

    The second vulnerability is also an SSO authentication bypass, but this time in FortiWeb. It stems from a similar bug with the cryptographic signature validation of SAML messages. This one is tracked as CVE-2025-59719 and also has a severity score of 9.8/10 (critical).

    Affected versions include:

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    8.0.0
    7.6.0 through 7.5.4,
    7.4.0 through 7.4.9.

    At the same time, security researchers Arctic Wolf are saying cybercriminals started exploiting the bugs on December 12 and using them to download system configuration files. That allows them to expose network layouts, internet-facing appliances, firewall settings, and possibly even hashed passwords.

    To defend from such intrusions, Fortinet suggests admins running vulnerable versions disable the FortiCloud login feature, and upgrade to a cleaner version as soon as possible, including any of these:

    FortiOS 7.6.4+, 7.4.9+, 7.2.12+, and 7.0.18+
    FortiProxy 7.6.4+, 7.4.11+, 7.2.15+, 7.0.22+
    FortiSwitchManager 7.2.7+, 7.0.6+
    FortiWeb 8.0.1+, 7.6.5+, 7.4.10+


    Best antivirus software header

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.



    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Which phone-powered PC experience is better?

    March 14, 2026

    How to upgrade your car’s old audio system to work with Android Auto and Apple CarPlay

    March 14, 2026

    How to Make a Killing review: a serial killer story should not be this boring

    March 14, 2026

    iQOO Z11’s design revealed, pre-orders go live

    March 13, 2026

    Google Messages is rolling out a fix for its most annoying oversight

    March 13, 2026

    This receiver setting solved my all audio sync problems

    March 13, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    This Week’s Awesome Tech Stories From Around the Web (Through March 14)

    March 14, 2026

    Groov-e Neo Buds Review – Trusted Reviews

    March 14, 2026

    I avoided liquid cooling for years and that was a huge mistake

    March 14, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.