CVE-2025-59719: 
Fortinet FortiWeb vulnerability analysis and mitigation

Overview

CVE-2025-59719 is an improper verification of cryptographic signature vulnerability (CWE-347) in Fortinet FortiWeb that allows unauthenticated attackers to bypass FortiCloud SSO login authentication via a crafted SAML response message. It affects FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, and FortiWeb 7.4.0 through 7.4.9. The vulnerability was disclosed on December 9, 2025, and is closely related to CVE-2025-59718, which affects a broader set of Fortinet products (FortiOS, FortiProxy, FortiSwitchManager). It carries a CVSS v3.1 base score of 9.8 (Critical) (Fortiguard PSIRT, Feedly).

Technical details

The root cause is improper verification of cryptographic signatures in SAML message processing (CWE-347), specifically within the FortiCloud SSO login feature. An attacker can craft a malicious SAML response that bypasses signature validation, effectively impersonating any user — including administrators — without valid credentials. Exploitation requires no privileges and no user interaction; the only precondition is that the FortiCloud SSO login feature is enabled on the device (it is not enabled by default, but is activated when an administrator registers the device to FortiCare via the GUI without explicitly disabling the toggle). A technical analysis of the SAML bypass mechanism was published by OPSWAT, and the attack vector is network-accessible (Fortiguard PSIRT, OPSWAT Analysis).

Impact

Successful exploitation grants an unauthenticated attacker full administrative access to affected FortiWeb instances via the FortiCloud SSO interface. Observed real-world attacks have resulted in unauthorized firewall configuration changes, exfiltration of firewall configurations, theft of service account credentials (including LDAP connection passwords), and subsequent lateral movement into internal networks — including Active Directory compromise. Over 25,000 FortiCloud SSO-enabled devices were identified as internet-exposed at the time of active exploitation (Arctic Wolf, BleepingComputer, SentinelOne).

Exploitability

CVE-2025-59719 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog shortly after disclosure in December 2025. Exploitation began within days of the patch release, with Arctic Wolf observing malicious SSO logins and automated attack campaigns targeting FortiGate devices at scale. Fortinet confirmed in January 2026 that even fully patched devices were being compromised, indicating a related zero-day (CVE-2026-24858) was also being leveraged. The EPSS score is approximately 0.00096. No public PoC code has been confirmed, but exploitation has been described as automated and widespread (CISA KEV, Rapid7 ETR, SecurityWeek).

Exploitation steps

  1. Reconnaissance: Identify internet-facing FortiWeb or FortiGate devices with FortiCloud SSO enabled using tools like Shodan or Censys, targeting the affected version ranges (FortiWeb 7.4.0–7.4.9, 7.6.0–7.6.4, 8.0.0).
  2. Identify SSO login endpoint: Locate the FortiCloud SSO login interface on the target device, which is accessible via the administrative GUI when the feature is enabled.
  3. Craft malicious SAML response: Construct a SAML response message with a forged or improperly signed assertion that impersonates an administrative user. Because the device fails to properly verify the cryptographic signature, the forged assertion is accepted.
  4. Submit crafted SAML response: Send the crafted SAML response to the FortiCloud SSO authentication endpoint. The device processes the response without valid signature verification and grants administrative access.
  5. Achieve admin access: The attacker gains full administrative control of the FortiWeb/FortiGate device, enabling them to modify firewall configurations, extract credentials (e.g., LDAP service account passwords stored in the config), and pivot into the internal network.
  6. Post-exploitation: Use stolen service account credentials for lateral movement into Active Directory or other internal systems; exfiltrate firewall configurations for further network reconnaissance (Fortiguard PSIRT, Arctic Wolf, CERT.at).

Indicators of compromise

  • Network: Unexpected inbound SAML authentication requests to the FortiCloud SSO login endpoint from unknown or suspicious IP addresses; outbound connections from FortiGate/FortiWeb devices to unfamiliar external hosts following SSO login events.
  • Logs: FortiGate/FortiWeb authentication logs showing successful SSO logins from unrecognized accounts or at unusual times; log entries indicating administrative configuration changes immediately following SSO authentication events; LDAP authentication attempts using service account credentials sourced from firewall configurations.
  • File System / Configuration: Unauthorized changes to firewall policies, admin accounts, or VPN configurations; new administrative accounts created via SSO; firewall configuration files accessed or exported without authorization.
  • Process / Behavior: Automated, high-volume SSO login attempts across multiple devices in a short timeframe (indicative of scripted/automated attack campaigns); rogue workstations or new device registrations appearing in Active Directory following FortiGate compromise (Arctic Wolf, SentinelOne, Kaspersky SIEM Rules).

Mitigation and workarounds

Fortinet released patched versions addressing CVE-2025-59719: FortiWeb 8.0.1 or above, FortiWeb 7.6.5 or above, and FortiWeb 7.4.10 or above. As an immediate workaround for unpatched systems, disable the FortiCloud SSO login feature via the GUI (System → Settings → disable 'Allow administrative login using FortiCloud SSO') or via CLI (config system global; set admin-forticloud-sso-login disable; end). Organizations should also audit SSO login logs for suspicious activity, rotate any service account credentials that may have been exposed, and implement network segmentation to limit administrative access to FortiWeb management interfaces. CISA has urged immediate patching given active exploitation (Fortiguard PSIRT, CISA Alert).

Community reactions

Fortinet published an official PSIRT advisory (FG-IR-25-647) and a dedicated blog post analyzing SSO abuse on FortiOS, confirming active exploitation including on fully patched devices in January 2026. Arctic Wolf published multiple threat intelligence reports documenting malicious SSO logins and automated configuration-change campaigns. Rapid7, SecurityWeek, BleepingComputer, The Hacker News, and Cybersecurity Dive all covered the active exploitation extensively. CISA issued an alert and added the vulnerability to its KEV catalog. The security community on Reddit (r/msp, r/blueteamsec) expressed significant concern, with MSPs noting the recurring pattern of critical Fortinet authentication bypass vulnerabilities. Kaspersky published SIEM detection rules specifically for this vulnerability (Fortinet Blog, Arctic Wolf, Kaspersky SIEM Rules).

Additional resources


Source: This report was generated using AI

Related Fortinet FortiWeb vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-26035CRITICAL9.8
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-40688HIGH7.2
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-39814MEDIUM6.7
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-39811MEDIUM4.9
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management