CVE-2025-59718: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the…
How it works
The weakness is classified as CWE-347, improper verification of cryptographic signature. In normal operation the affected products validate the digital signature on incoming SAML assertions before granting access through FortiCloud SSO. When verification is incomplete or incorrectly implemented, an attacker can supply a SAML message whose signature is not properly checked. The product then treats the assertion as trustworthy and issues an authenticated session without requiring valid credentials from the identity provider.
Am I affected? How to find it in your systems
Inventory all Fortinet appliances that participate in FortiCloud SSO, including FortiOS firewalls, FortiProxy instances, FortiWeb web-application firewalls, and FortiSwitchManager deployments. Confirm whether FortiCloud SSO is enabled and which identity providers are configured. Review the vendor advisory for the precise versions and configuration settings that require attention. Examine authentication logs for SAML responses that originate from unexpected sources or contain signature-related anomalies; correlate these events with successful logins that bypass expected multi-factor or identity-provider checks.
How to remediate
Apply the vendor updates listed in the official advisory. After patching, verify that signature validation settings for SAML assertions remain at their strictest supported values and that any optional “accept unsigned” or “skip validation” toggles are disabled. Re-test FortiCloud SSO flows from each configured identity provider to confirm that only correctly signed assertions are accepted.
If you can't patch immediately
- Follow the mitigations documented in the vendor advisory.
- Apply CISA BOD 22-01 guidance for any cloud services involved in the SSO chain.
- Segment management and authentication traffic so that only trusted identity-provider endpoints can reach the affected Fortinet devices.
- Monitor SAML endpoints for high volumes of failed or malformed assertions and alert on successful authentications that lack corresponding identity-provider records.
- Consider temporarily disabling FortiCloud SSO in favor of local authentication or an alternative identity provider until patches can be deployed.
If your data may have been exposed
Successful exploitation of this class of vulnerability can result in unauthorized access. Organizations should review authentication logs for suspicious FortiCloud SSO activity and run a free exposure scan of their domains to check for known breach data associated with affected accounts.
AICompiled with AI assistance from public sources and published under our editorial standards.