A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-647 | Vendor Advisory |
| https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718 | US Government Resource |
Configurations
Configuration 1 (hide)
|
History
17 Dec 2025, 13:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/ - Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718 - US Government Resource |
16 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Dec 2025, 20:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-647 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* |
|
| First Time |
Fortinet
Fortinet fortiproxy Fortinet fortios Fortinet fortiswitchmanager |
09 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 18:15
Updated : 2025-12-17 13:54
NVD link : CVE-2025-59718
Mitre link : CVE-2025-59718
CVE.ORG link : CVE-2025-59718
JSON object : View
Products Affected
fortinet
- fortiswitchmanager
- fortiproxy
- fortios
CWE
CWE-347
Improper Verification of Cryptographic Signature
