More

    Fortinet products hit by further security flaws – giving hackers access to systems and more



    • Two critical SAML‑signature flaws (CVE‑2025‑59718/59719) let attackers bypass SSO across multiple Fortinet products
    • Exploitation began December 12, with intruders pulling config files that expose network layouts and hashed passwords
    • Fortinet urges disabling FortiCloud login and upgrading immediately to the patched versions listed

    Two new critical vulnerabilities have been discovered in Fortinet products, and since they are being actively abused in the wild, both the company and security researchers are urging users to upgrade to the newest version as soon as possible.

    In a newly released security advisory (via BleepingComputer), Fortinet said it discovered an SSO authentication bypass bug in FortiOS, FortiProxy, and FortiSwitchManager, caused by improper verification of cryptographic signatures in SAML messages.


    https://cdn.mos.cms.futurecdn.net/oyKgE5jTrnx6fQA6dwPuCj-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img