🕳️ Vulnerabilities & CVEs

Inside the FortiGate Breach: CVE-2025-59718 Let Attackers Ghost In

Attackers cracked a FortiGate firewall via CVE-2025-59718, bypassed SSO, and prowled silently inside. Responders caught them mid-lateral move—here's the raw playbook.

FortiGate firewall logs showing anomalous internal IP authentication during CVE-2025-59718 exploitation

⚡ Key Takeaways

  • Attackers used CVE-2025-59718 for stealthy SSO bypass on FortiGate, mimicking admins perfectly. 𝕏
  • IR timeline reconstruction via 'inside-out' from alerts revealed the edge device as entry. 𝕏
  • Hunt anomalous DHCP IPs and Mimikatz for detection; patch and log deeply to prevent. 𝕏
Published by

CVE Watch

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by Rapid7 Blog

Stay in the loop

The week's most important stories from CVE Watch, delivered once a week.