peter bassill · operator
$ cve CVE-2025-59718 JSON

CVE-2025-59718 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 68.3% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-12-23.

Description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS68.29% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-347
On CISA KEVyes — remediate by 2025-12-23
Public exploitnone known
Published2025-12-09
Last modified2026-06-17

CISA KEV

NameFortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Added2025-12-16
Due2025-12-23
Vendor / productFortinet / Multiple Products
Ransomware usenone reported

Affected (5)

VendorProduct
fortinetfortios
fortinetfortiproxy
fortinetfortiswitchmanager
siemensruggedcom ape1808
siemensruggedcom ape1808 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD