
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59718 is a critical improper verification of cryptographic signature vulnerability (CWE-347) in Fortinet's FortiCloud SSO login authentication mechanism. It allows unauthenticated attackers to bypass FortiCloud SSO login by sending a crafted SAML response message. Affected products include FortiOS 7.0.0–7.0.17, 7.2.0–7.2.11, 7.4.0–7.4.8, and 7.6.0–7.6.3; FortiProxy 7.0.0–7.0.21, 7.2.0–7.2.14, 7.4.0–7.4.10, and 7.6.0–7.6.3; FortiSwitchManager 7.0.0–7.0.5 and 7.2.0–7.2.6; and FortiWeb across multiple versions. The vulnerability was disclosed on December 9, 2025, and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on December 16, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) (Fortinet PSIRT, CISA KEV).
The root cause is improper verification of cryptographic signatures in the SAML-based FortiCloud SSO authentication flow (CWE-347). When FortiCloud SSO is enabled, the affected products fail to properly validate the cryptographic signature of incoming SAML response messages, allowing an attacker to forge a valid-looking SAML assertion without possessing the legitimate signing key. The attack is network-based, requires no authentication, no user interaction, and low complexity — an attacker simply sends a crafted HTTP request containing a malicious SAML message to the management interface. The feature is not enabled by default but is commonly activated when administrators register devices to FortiCare via the GUI, unless the 'Allow administrative login using FortiCloud SSO' toggle is explicitly disabled during registration. A public PoC was published on GitHub (github.com/exfil0/CVE-2025-59718-PoC), and a technical analysis was published by OPSWAT (OPSWAT Analysis) and Rapid7 (Rapid7 ETR).
Successful exploitation grants an unauthenticated attacker complete administrative access to affected Fortinet security appliances, including FortiGate firewalls. Observed post-exploitation activity includes exfiltration of full firewall configurations (containing hashed credentials, network topology, and policy details), creation of rogue administrative accounts, and unauthorized modification of firewall rules. Over 25,000 internet-exposed devices were identified as vulnerable, and incident response findings revealed that attackers leveraged stolen service account credentials from compromised FortiGate devices to pivot into internal networks, compromise Active Directory environments, and deploy rogue workstations — enabling deep lateral movement (Arctic Wolf, SentinelOne, BleepingComputer).
Active exploitation was confirmed in the wild within days of the December 9, 2025 patch release, with Arctic Wolf observing malicious SSO logins beginning December 12, 2025. CISA added CVE-2025-59718 to its KEV catalog on December 16, 2025, with a remediation due date of December 23, 2025 (CISA KEV). A public PoC was published on GitHub, and automated attack campaigns were subsequently observed targeting FortiGate devices globally. Notably, Fortinet later confirmed in January 2026 that the initial patches were not fully effective, with exploitation continuing against devices running supposedly patched firmware versions (e.g., FortiOS 7.4.9), leading to disclosure of a related zero-day CVE-2026-24858 (BleepingComputer). The EPSS score is approximately 0.089%. The vulnerability has been linked to ransomware-adjacent campaigns, including activity by a Qilin affiliate (Ctrl-Alt-Intel). No specific nation-state attribution has been confirmed.
method="sso" and profile="super_admin".logid="0100032001", method="sso", ui="sso(<external_IP>)", action="login", status="success", and profile="super_admin" from unexpected source IPs. Subsequent entries with logid="0100032095", action="download", and msg indicating system config file download via GUI from the same external IP.Immediate workaround: Disable the FortiCloud SSO login feature by navigating to System → Settings and toggling 'Allow administrative login using FortiCloud SSO' to Off, or via CLI: config system global, set admin-forticloud-sso-login disable, end. This mitigates the attack vector without requiring a firmware upgrade (Fortinet PSIRT).
Patched versions (upgrade to these or later):
Important caveat: Fortinet confirmed in January 2026 that the initial patches were not fully effective and that exploitation continued on patched devices; a follow-on zero-day (CVE-2026-24858) was disclosed January 28, 2026. Administrators should verify they are running the latest available firmware and monitor for the related advisory. Additionally, restrict management interface access to trusted internal networks, reset credentials if compromise is suspected, and review audit logs for malicious SSO login indicators (BleepingComputer, CISA KEV).
Fortinet published a PSIRT blog post titled 'Analysis of SSO Abuse on FortiOS' in January 2026 acknowledging active exploitation and the incomplete patch situation (Fortinet Blog). Arctic Wolf was among the first to publicly document active exploitation, reporting malicious SSO logins beginning December 12, 2025 — just three days after patch release — and later observing a second wave of automated attacks in January 2026 involving configuration theft (Arctic Wolf). Rapid7, SecurityWeek, BleepingComputer, The Hacker News, and Dark Reading all covered the vulnerability extensively, with SecurityWeek noting a 'new wave of attacks' in January 2026 (SecurityWeek). The MSP and Fortinet administrator communities on Reddit expressed significant frustration, particularly after reports emerged that fully patched devices were still being compromised. Kaspersky published SIEM detection rules to help defenders identify exploitation attempts (Kaspersky). The vulnerability was widely cited as emblematic of the broader 2025 trend of network edge device exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."