Vulnerability record · CVE-2025-59718 · published 9 December 2025
CVE-2025-59718: Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSO
Fortinet · Fortiproxy
FortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An unauthenticated remote attacker can forge a SAML response and bypass authentication entirely. The flaw affects a wide range of FortiOS, FortiProxy and FortiSwitchManager releases and is listed in CISA KEV, so it warrants urgent attention.
Description
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a near-term due date, high EPSS and reported in-the-wild SSO logins make this an urgent authentication bypass.
What it is
FortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An unauthenticated remote attacker can forge a SAML response and bypass authentication entirely. The flaw affects a wide range of FortiOS, FortiProxy and FortiSwitchManager releases and is listed in CISA KEV, so it warrants urgent attention.
Impact
An attacker gains authenticated access to the management interface without valid credentials, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full administrative control of the affected device.
Attack surface
Reachable over the network via the FortiCloud SSO login flow; the CVSS vector shows no privileges and no user interaction required. Any internet-exposed management interface using FortiCloud SSO is a candidate target.
Exploitation
CVE-2025-59718 is in CISA KEV with a due date of 2025-12-23, and EPSS is 0.68 (99th percentile), indicating active exploitation is expected or observed. A third-party advisory reports malicious SSO logins following disclosure.
What to do
- Apply the Fortinet vendor patches referenced in FG-IR-25-647 for all affected FortiOS, FortiProxy and FortiSwitchManager versions.
- If patching is not immediately possible, disable FortiCloud SSO authentication on management interfaces or restrict management access to trusted networks.
- Follow CISA BOD 22-01 guidance for cloud services and the KEV required action, including discontinuing use if mitigations are unavailable.
- Review Siemens advisory SSA-864900 for any Ruggedcom AP1808 exposure and apply the corresponding fix.
- Audit and rotate administrative credentials and sessions on devices that may have been exposed.
Detection
- Search authentication logs for successful FortiCloud SSO logins from unexpected source IPs or at unusual times.
- Alert on SAML responses with invalid or missing signatures reaching the SSO endpoint.
- Monitor for new or changed admin accounts and configuration changes on FortiOS, FortiProxy and FortiSwitchManager devices.
- Correlate management-plane logins with threat intelligence for known exploitation activity following the December 2025 disclosure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-59718 to the Known Exploited Vulnerabilities catalog on 16 December 2025 as "Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 December 2025.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-647 | Vendor Advisory |
| https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve- | Third Party Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-864900.html | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718 | US Government Resource |
Track CVE-2025-59718 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-59718), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.