LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-59718: Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 16, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog on Dec 16, 2025, with a federal patch deadline of Dec 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the…

Fortinet FortiOS, FortiSwitchManager, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability. An unauthenticated attacker may bypass FortiCloud SSO login authentication by presenting a crafted SAML message. The issue is tracked as CVE-2025-59718 and is addressed in the same advisory as the related CVE-2025-59719. Organizations that rely on these products for identity federation should treat the flaw as a direct authentication bypass risk.

How it works

The weakness is classified as CWE-347, improper verification of cryptographic signature. In normal operation the affected products validate the digital signature on incoming SAML assertions before granting access through FortiCloud SSO. When verification is incomplete or incorrectly implemented, an attacker can supply a SAML message whose signature is not properly checked. The product then treats the assertion as trustworthy and issues an authenticated session without requiring valid credentials from the identity provider.

Am I affected? How to find it in your systems

Inventory all Fortinet appliances that participate in FortiCloud SSO, including FortiOS firewalls, FortiProxy instances, FortiWeb web-application firewalls, and FortiSwitchManager deployments. Confirm whether FortiCloud SSO is enabled and which identity providers are configured. Review the vendor advisory for the precise versions and configuration settings that require attention. Examine authentication logs for SAML responses that originate from unexpected sources or contain signature-related anomalies; correlate these events with successful logins that bypass expected multi-factor or identity-provider checks.

How to remediate

Apply the vendor updates listed in the official advisory. After patching, verify that signature validation settings for SAML assertions remain at their strictest supported values and that any optional “accept unsigned” or “skip validation” toggles are disabled. Re-test FortiCloud SSO flows from each configured identity provider to confirm that only correctly signed assertions are accepted.

If you can't patch immediately

If your data may have been exposed

Successful exploitation of this class of vulnerability can result in unauthorized access. Organizations should review authentication logs for suspicious FortiCloud SSO activity and run a free exposure scan of their domains to check for known breach data associated with affected accounts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · Multiple Products
WeaknessCWE-347
Added to CISA KEVDec 16, 2025
Federal patch deadlineDec 23, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities