Attackers are exploiting auth bypass vulnerability on FortiGate firewalls (CVE-2025-59718)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-59718 | Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days. Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01. | 9.8 | 68% | KEV |
| masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the… | |
| CVE-2025-59719 | Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO) FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible. Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent. | 9.8 | 29% |
| largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud… |
Full article455 words · extracted from helpnetsecurity.com · click to collapse
Attackers are exploiting a recently revealed vulnerability (CVE-2025-59718) to bypass authentication on Fortinet’s FortiGate firewalls, and are leveraging the achieved access to export their system configuration files, Arctic Wolf researchers warned on Tuesday.
Configuration files can expose information about the underlying network and infrastructure, firewall and security policies, encrypted/hashed passwords, and more. Some of this data can come in handy for executing successfuly attacks at a later date.
CVE-2025-59718 and CVE-2025-59719
Fortinet discovered CVE-2025-59718 and CVE-2025-59719 internally and patched them earlier this year.
Both flaws stem from improper verification of cryptographic signatures. They can be exploited by sending a specially crafted SAML response message to a vulnerable device, which effectively “tells” it that the user initiating the request should be granted access.
CVE-2025-59718 affects FortiOS (running on FortiGate firewalls), FortiProxy (running on FortiProxy secure web gateways), and FortiSwitchManager (running on appliances that are used to centrally manage FortiSwitch Ethernet switches).
CVE-2025-59719 affects FortiWeb, Fortinet’s web application firewall.
The company revealed the vulnerabilities’ existence on December 9, 2025, and urged customers to upgrade to a fixed version or “turn off the FortiCloud login feature (if enabled) temporarily until upgrading to a non-affected version.”
Fortinet noted that the FortiCloud SSO login feature is not enabled in default factory settings, but gets switched on if an administrator uses the device’s GUI to register the device to FortiCare – Fortinet’s customer support and maintenance service – but doesn’t disable the “Allow administrative login using FortiCloud SSO” option in the registration page.
Action required
Arctic Wolf says that it started observing intrusions involving malicious SSO logins on FortiGate appliances on December 12.
The SAML response messages were sent from various IP addresses tied to several hosting providers.
“Malicious logins were typically against the admin account,” the company noted. “Following malicious SSO logins, configurations were exported to the same IP addresses via the GUI interface. ”
Organizations using FortiGate firewalls that have yet to upgrade to a non-vulnerable version and are using the FortiCloud SSO login feature should check their logs for suspicious logins and known indicators of compromise.
“If you observe malicious activity similar to the malicious logs described in this security bulletin, assume that hashed firewall credentials stored in the exfiltrated configurations have been compromised, and reset those credentials as soon as possible,” Arctic Wolf researchers advised.
They also urged admins in charge of their organization’s network appliances to limit access to management interfaces of firewall and VPN appliances to trusted internal users.
CISA has added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog and requires US federal civilian agencies to remediate the flaw by December 23, 2025.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/17/fortigate-vulnerability-cve-2025-59718-exploited/