Affected Systems

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from configuration data.

Exploitation Status

Active exploitation confirmed. CERT.at reports threat actors are using toolkits to exploit these vulnerabilities in the wild. Attackers leverage the static encryption key to decrypt sensitive configuration data.

Business Impact

Organizations using FortiGate with FortiCloud SSO face immediate credential theft risk. Compromised LDAP passwords enable lateral movement into Active Directory and other directory services. Extracted private keys may expose VPN and certificate-based authentication. This is a critical supply chain weakness affecting all FortiGate deployments due to the shared static encryption key.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately disable FortiCloud SSO on all FortiGate appliances until patches are applied
  • Apply Fortinet security updates for CVE-2025-59718 and CVE-2025-59719 as soon as available
  • Rotate all LDAP service account passwords and monitor Active Directory for suspicious authentication attempts
  • Review FortiGate logs for unauthorized configuration access or SSO authentication anomalies
  • Audit and rotate private keys and certificates stored in FortiGate configurations

---

# Threat Actor Context

Actor Profile

Attribution remains unknown. The threat actor demonstrates advanced knowledge of Fortinet appliance architecture, specifically targeting FortiCloud SSO authentication bypass vulnerabilities (CVE-2025-59718, CVE-2025-59719) to extract LDAP credentials. Motivation appears focused on credential harvesting for potential lateral movement into enterprise networks. The exploitation of default static encryption keys indicates either prior insider knowledge or reverse engineering of FortiGate firmware. The actor's toolkit suggests a sophisticated understanding of Fortinet's cryptographic implementation flaws.

TTPs (Tactics, Techniques, Procedures)

Initial Access: T1190 (Exploit Public-Facing Application) via FortiCloud SSO bypass vulnerabilities. Credential Access: T1552.001 (Credentials In Files) through extraction of encrypted configuration data; T1555 (Credentials from Password Stores) targeting LDAP connection passwords. Defense Evasion: Exploitation of default static encryption key (T1140 Deobfuscate/Decode Files or Information) to decrypt sensitive configuration including LDAP credentials and private keys. The attack chain relies on cryptographic weaknesses in FortiGate's default configuration rather than traditional malware deployment.

Targets & Patterns

Primary targets are technology and infrastructure sectors in Austria, specifically organizations deploying Fortinet FortiGate appliances with FortiCloud SSO integration. The focus on LDAP credential extraction suggests targeting enterprises with Active Directory environments where compromised LDAP credentials enable domain-wide access. Infrastructure sector targeting indicates potential interest in critical national infrastructure where Fortinet solutions are commonly deployed for perimeter security. The attack pattern suggests opportunistic exploitation of vulnerable internet-facing FortiGate instances rather than highly selective targeting, though sector concentration may indicate regional reconnaissance or specific operational objectives.

Historical Context

This campaign represents a continuation of sustained adversary interest in Fortinet vulnerabilities. Previous campaigns have exploited FortiOS flaws including CVE-2022-40684 (authentication bypass), CVE-2023-27997 (heap buffer overflow), and CVE-2024-21762 (out-of-bounds write). The exploitation of default cryptographic keys echoes historical attacks against vendor appliances with hardcoded credentials. CERT.at's disclosure indicates active exploitation in the wild, though no specific attribution to known APT groups has been established. The credential harvesting objective aligns with initial access broker activity observed in ransomware supply chains.

Defensive Recommendations

  • Immediately patch CVE-2025-59718 and CVE-2025-59719 on all FortiGate appliances with FortiCloud SSO enabled; prioritize internet-facing instances
  • Audit FortiGate configuration exports for unauthorized access; monitor for T1552.001 indicators including unexpected configuration file reads or downloads
  • Rotate all LDAP service account credentials and private keys stored in FortiGate configurations, assuming compromise if vulnerable versions were exposed
  • Implement network segmentation to limit LDAP credential utility; enforce least-privilege for service accounts and enable LDAP signing/channel binding (LDAPS)
  • Deploy detection for T1190 exploitation attempts via FortiCloud SSO endpoints; monitor authentication logs for anomalous SSO bypass patterns and failed authentication spikes

---

# Geopolitical Context

Geopolitical Context

The exploitation of FortiCloud SSO bypass vulnerabilities (CVE-2025-59718/CVE-2025-59719) represents a significant supply chain security risk affecting enterprise and critical infrastructure networks globally. Fortinet appliances are widely deployed across government, defense, and corporate environments, making systematic exploitation of a vendor-wide static encryption key a strategic concern. CERT.at's disclosure indicates active exploitation in Austria, though the universal nature of the vulnerability—stemming from a default static key present on all FortiGate instances—suggests potential for widespread compromise across multiple jurisdictions. The ability to extract LDAP credentials and private keys enables adversaries to pivot into Active Directory environments and establish persistent access to organizational networks. The incident underscores ongoing challenges in securing network perimeter devices and the cascading risks when cryptographic implementations rely on shared secrets across product lines.

State Actor Alignment

Attribution remains unconfirmed. The sophistication of the toolkit—leveraging knowledge of Fortinet's default cryptographic implementation to systematically extract credentials—is consistent with capabilities observed in both state-sponsored advanced persistent threat (APT) groups and organized cybercrime actors. Fortinet devices have historically been targeted by groups linked to China (APT41, Volt Typhoon) and Russia (APT28, Sandworm) for initial access to government and critical infrastructure networks. However, the public disclosure by CERT.at and the nature of the vulnerability may also attract opportunistic exploitation by a broader range of actors. No government has issued formal attribution or sanctions related to this specific campaign. Organizations in NATO member states and critical infrastructure sectors should treat this as a potential national security concern pending further intelligence.

Business Impacty pro region

The vulnerability poses acute risks to European critical infrastructure and government networks, where Fortinet solutions maintain significant market share in network security. Austria's CERT disclosure may indicate either localized targeting or early detection of a broader campaign. The static key vulnerability affects all FortiGate instances globally, creating systemic risk across NATO allies, EU institutions, and partner nations. Extraction of LDAP credentials enables adversaries to compromise identity management systems, potentially affecting cross-border information sharing and classified networks. The incident arrives amid heightened European focus on supply chain security following the EU Cyber Resilience Act and NIS2 Directive implementation. Countries with significant Fortinet deployments in energy, telecommunications, and defense sectors—including Germany, France, the United Kingdom, and the United States—face elevated risk of credential harvesting and lateral movement campaigns. The vulnerability may also be exploited in targeting of diplomatic missions and international organizations headquartered in Europe.

Forecast

If Fortinet does not issue emergency patches and organizations fail to rotate LDAP credentials and private keys extracted from affected devices, widespread compromise of enterprise identity systems is likely in the coming weeks. Threat actors with access to extracted credentials may establish persistent access to government and critical infrastructure networks before detection, enabling espionage or pre-positioning for disruptive operations. If state-sponsored groups are responsible, the campaign may expand to target defense industrial base entities and energy infrastructure as geopolitical tensions persist. Expect increased scanning activity for vulnerable FortiGate instances and potential publication of exploitation tools in criminal forums, broadening the threat actor base. If CERT.at's disclosure prompts coordinated incident response across Europe, detection of additional compromises in neighboring countries is probable. Organizations that delay patching and credential rotation face elevated risk of ransomware deployment or data exfiltration in the near term.