
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59719 is an improper verification of cryptographic signature vulnerability (CWE-347) in Fortinet FortiWeb that allows unauthenticated attackers to bypass FortiCloud SSO login authentication via a crafted SAML response message. It affects FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, and FortiWeb 7.4.0 through 7.4.9. The vulnerability was disclosed on December 9, 2025, and is closely related to CVE-2025-59718, which affects a broader set of Fortinet products (FortiOS, FortiProxy, FortiSwitchManager). It carries a CVSS v3.1 base score of 9.8 (Critical) (Fortiguard PSIRT, Feedly).
The root cause is improper verification of cryptographic signatures in SAML message processing (CWE-347), specifically within the FortiCloud SSO login feature. An attacker can craft a malicious SAML response that bypasses signature validation, effectively impersonating any user — including administrators — without valid credentials. Exploitation requires no privileges and no user interaction; the only precondition is that the FortiCloud SSO login feature is enabled on the device (it is not enabled by default, but is activated when an administrator registers the device to FortiCare via the GUI without explicitly disabling the toggle). A technical analysis of the SAML bypass mechanism was published by OPSWAT, and the attack vector is network-accessible (Fortiguard PSIRT, OPSWAT Analysis).
Successful exploitation grants an unauthenticated attacker full administrative access to affected FortiWeb instances via the FortiCloud SSO interface. Observed real-world attacks have resulted in unauthorized firewall configuration changes, exfiltration of firewall configurations, theft of service account credentials (including LDAP connection passwords), and subsequent lateral movement into internal networks — including Active Directory compromise. Over 25,000 FortiCloud SSO-enabled devices were identified as internet-exposed at the time of active exploitation (Arctic Wolf, BleepingComputer, SentinelOne).
CVE-2025-59719 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog shortly after disclosure in December 2025. Exploitation began within days of the patch release, with Arctic Wolf observing malicious SSO logins and automated attack campaigns targeting FortiGate devices at scale. Fortinet confirmed in January 2026 that even fully patched devices were being compromised, indicating a related zero-day (CVE-2026-24858) was also being leveraged. The EPSS score is approximately 0.00096. No public PoC code has been confirmed, but exploitation has been described as automated and widespread (CISA KEV, Rapid7 ETR, SecurityWeek).
Fortinet released patched versions addressing CVE-2025-59719: FortiWeb 8.0.1 or above, FortiWeb 7.6.5 or above, and FortiWeb 7.4.10 or above. As an immediate workaround for unpatched systems, disable the FortiCloud SSO login feature via the GUI (System → Settings → disable 'Allow administrative login using FortiCloud SSO') or via CLI (config system global; set admin-forticloud-sso-login disable; end). Organizations should also audit SSO login logs for suspicious activity, rotate any service account credentials that may have been exposed, and implement network segmentation to limit administrative access to FortiWeb management interfaces. CISA has urged immediate patching given active exploitation (Fortiguard PSIRT, CISA Alert).
Fortinet published an official PSIRT advisory (FG-IR-25-647) and a dedicated blog post analyzing SSO abuse on FortiOS, confirming active exploitation including on fully patched devices in January 2026. Arctic Wolf published multiple threat intelligence reports documenting malicious SSO logins and automated configuration-change campaigns. Rapid7, SecurityWeek, BleepingComputer, The Hacker News, and Cybersecurity Dive all covered the active exploitation extensively. CISA issued an alert and added the vulnerability to its KEV catalog. The security community on Reddit (r/msp, r/blueteamsec) expressed significant concern, with MSPs noting the recurring pattern of critical Fortinet authentication bypass vulnerabilities. Kaspersky published SIEM detection rules specifically for this vulnerability (Fortinet Blog, Arctic Wolf, Kaspersky SIEM Rules).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."