← Vulnerability feed

Vulnerability record · CVE-2025-59718 · published 9 December 2025

CVE-2025-59718: Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSO

Fortinet · Fortiproxy

FortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An unauthenticated remote attacker can forge a SAML response and bypass authentication entirely. The flaw affects a wide range of FortiOS, FortiProxy and FortiSwitchManager releases and is listed in CISA KEV, so it warrants urgent attention.

9.8 CVSS 3.1 Critical CISA KEV since 16 Dec 2025 EPSS 68% · top 0.7% CWE-347 · Improper verification of cryptographic signature
9.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with a near-term due date, high EPSS and reported in-the-wild SSO logins make this an urgent authentication bypass.

What it is

FortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An unauthenticated remote attacker can forge a SAML response and bypass authentication entirely. The flaw affects a wide range of FortiOS, FortiProxy and FortiSwitchManager releases and is listed in CISA KEV, so it warrants urgent attention.

Impact

An attacker gains authenticated access to the management interface without valid credentials, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full administrative control of the affected device.

Attack surface

Reachable over the network via the FortiCloud SSO login flow; the CVSS vector shows no privileges and no user interaction required. Any internet-exposed management interface using FortiCloud SSO is a candidate target.

Exploitation

CVE-2025-59718 is in CISA KEV with a due date of 2025-12-23, and EPSS is 0.68 (99th percentile), indicating active exploitation is expected or observed. A third-party advisory reports malicious SSO logins following disclosure.

What to do

  • Apply the Fortinet vendor patches referenced in FG-IR-25-647 for all affected FortiOS, FortiProxy and FortiSwitchManager versions.
  • If patching is not immediately possible, disable FortiCloud SSO authentication on management interfaces or restrict management access to trusted networks.
  • Follow CISA BOD 22-01 guidance for cloud services and the KEV required action, including discontinuing use if mitigations are unavailable.
  • Review Siemens advisory SSA-864900 for any Ruggedcom AP1808 exposure and apply the corresponding fix.
  • Audit and rotate administrative credentials and sessions on devices that may have been exposed.

Detection

  • Search authentication logs for successful FortiCloud SSO logins from unexpected source IPs or at unusual times.
  • Alert on SAML responses with invalid or missing signatures reaching the SSO endpoint.
  • Monitor for new or changed admin accounts and configuration changes on FortiOS, FortiProxy and FortiSwitchManager devices.
  • Correlate management-plane logins with threat intelligence for known exploitation activity following the December 2025 disclosure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-59718 to the Known Exploited Vulnerabilities catalog on 16 December 2025 as "Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 December 2025.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59718 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2024-55591FortiOS and FortiProxy authentication bypass via Node.js websocketFortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable throug…KEVEPSS 94%analysed9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed9.8CVE-2024-21762Fortinet FortiOS and FortiProxy out-of-bounds write in SSL VPNFortiOS and FortiProxy contain an out-of-bounds write (CWE-787) reachable through specifically crafted requests. The flaw affects a wide range of For…KEVEPSS 83%analysed9.8CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN heap buffer overflowFortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow (CWE-122/CWE-787) reachable through specifically crafted requests. It is a pre-au…KEVEPSS 86%analysed9.8CVE-2022-42475FortiOS and FortiProxy SSL-VPN heap buffer overflow allows remote code executionA heap-based buffer overflow (CWE-122/CWE-787) in the FortiOS and FortiProxy SSL-VPN component lets a remote attacker trigger memory corruption throu…KEVEPSS 99%analysed9.8CVE-2022-40684Fortinet FortiOS, FortiProxy and FortiSwitchManager admin interface auth bypassAn authentication bypass (CWE-288, alternate path or channel) in Fortinet FortiOS 7.2.0-7.2.1 and 7.0.0-7.0.6, FortiProxy 7.2.0 and 7.0.0-7.0.6, and …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59718), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.