CVE-2025-59718 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 68.3% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2025-12-23.
Description
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 68.29% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-347 |
| On CISA KEV | yes — remediate by 2025-12-23 |
| Public exploit | none known |
| Published | 2025-12-09 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability |
|---|---|
| Added | 2025-12-16 |
| Due | 2025-12-23 |
| Vendor / product | Fortinet / Multiple Products |
| Ransomware use | none reported |
Affected (5)
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortiproxy |
| fortinet | fortiswitchmanager |
| siemens | ruggedcom ape1808 |
| siemens | ruggedcom ape1808 firmware |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-25-647
- https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/
- https://cert-portal.siemens.com/productcert/html/ssa-864900.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718
→ the Explorer · watch your stack · NVD