ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-59718CVE-2025-59719

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59718
Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy

CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days.

Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01.

9.868% KEV
  • Fortinet FortiOS 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3
  • Fortinet FortiProxy 7.0.0-7.0.21, 7.2.0-7.2.14, 7.4.0-7.4.10, 7.6.0-7.6.3
  • Fortinet FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6
  • +1 more
masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the…
CVE-2025-59719
Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO)

FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible.

Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent.

9.829%
  • fortinet fortiweb 8.0.0
  • fortinet fortiweb 7.6.0 through 7.6.4
  • fortinet fortiweb 7.4.0 through 7.4.9
largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud…
Full article746 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 17, 2025

U.S. CISA adds a vulnerability impacting multiple products to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability, tracked as CVE-2025-59718 (CVSS Score of 9.1), to its Known Exploited Vulnerabilities (KEV) catalog.

Threat actors started exploiting two critical flaws, tracked as CVE-2025-59718 and CVE-2025-59719 (CVSS score of 9.1), in Fortinet products days after patch release, Arctic Wolf warns.

Last week, Fortinet addressed 18 vulnerabilities, including the two flaws CVE-2025-59718 and CVE-2025-59719, affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager when FortiCloud SSO is enabled.

Both vulnerabilities are improper verification of cryptographic signature issues.

An improper signature-verification flaw in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager lets an unauthenticated attacker bypass FortiCloud SSO login using a crafted SAML message, if the feature is enabled. FortiCloud SSO is disabled by default, but it activates automatically during FortiCare registration unless the admin disables the “Allow administrative login using FortiCloud SSO” toggle.

“Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an administrator registers the device to FortiCare from the device’s GUI, unless the administrator disables the toggle switch “Allow administrative login using FortiCloud SSO” in the registration page, FortiCloud SSO login is enabled upon registration.” reads the advisory.

The vendor recommends disabling the FortiCloud login feature (if enabled) until upgrading to a non-affected version, as a temporary mitigation.

Below are the impacted versions:

VersionAffectedSolution
FortiOS 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiOS 7.47.4.0 through 7.4.8Upgrade to 7.4.9 or above
FortiOS 7.27.2.0 through 7.2.11Upgrade to 7.2.12 or above
FortiOS 7.07.0.0 through 7.0.17Upgrade to 7.0.18 or above
FortiOS 6.4Not affectedNot Applicable
FortiProxy 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiProxy 7.47.4.0 through 7.4.10Upgrade to 7.4.11 or above
FortiProxy 7.27.2.0 through 7.2.14Upgrade to 7.2.15 or above
FortiProxy 7.07.0.0 through 7.0.21Upgrade to 7.0.22 or above
FortiSwitchManager 7.27.2.0 through 7.2.6Upgrade to 7.2.7 or above
FortiSwitchManager 7.07.0.0 through 7.0.5Upgrade to 7.0.6 or above
FortiWeb 8.08.0.0Upgrade to 8.0.1 or above
FortiWeb 7.67.6.0 through 7.6.4Upgrade to 7.6.5 or above
FortiWeb 7.47.4.0 through 7.4.9Upgrade to 7.4.10 or above
FortiWeb 7.2Not affectedNot Applicable
FortiWeb 7.0Not affectedNot Applicable

The vulnerabilities were internally discovered and reported by Yonghui Han and Theo Leleu of Fortinet Product Security team.

Arctic Wolf researchers observed attackers began exploiting critical Fortinet authentication bypass flaws on December 12, just three days after patches were issued. The attacks involved malicious SSO logins on FortiGate devices, mainly targeting admin accounts from multiple hosting providers. After gaining access, the attackers exported device configurations via the GUI. These files include hashed credentials, which threat actors can attempt to crack offline, increasing the risk of further compromise.

“In December 12, 2025, Arctic Wolf began observing intrusions involving malicious SSO logins on FortiGate appliances. Fortinet had previously released an advisory for two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) on December 9, 2025. Arctic Wolf had also sent out a security bulletin for the vulnerabilities shortly thereafter.” Arctic Wolf warns.

The experts reported that recent intrusions involved malicious SSO logins to FortiGate devices originating from a small set of hosting providers. Attackers primarily targeted the admin account, successfully authenticating via SSO from specific IP addresses. After gaining access, they used the FortiGate GUI to download device configuration files, exporting them to the same source IPs. Arctic Wolf reports having detection mechanisms in place to identify this activity and will continue monitoring and alerting customers about further suspected exploitation.

Administrators are urged to check for signs of compromise, reset credentials if needed, and restrict firewall management access to trusted networks. Fortinet has released patches across multiple FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb versions, and advises disabling FortiCloud SSO admin login to mitigate exploitation risks.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by December 23, 2025.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185765/security/u-s-cisa-adds-a-flaw-in-multiple-fortinet-products-to-its-known-exploited-vulnerabilities-catalog.html