← Back to browse · API

CVE-2025-59718

Severity
CRITICAL
CVSS
9.1
EPSS
0.63443
Risk score
83.61
CISA KEV
Yes
PoC
No
Published
2025-12-16
Modified
2025-12-16
First seen
2026-08-07
Aliases
EUVD-2025-202198, GHSA-FJJ2-P33C-F8QQ
Products
Fortinet:FortiOS 7.0.0 ≤7.0.17, Fortinet:FortiOS 7.2.0 ≤7.2.11, Fortinet:FortiOS 7.4.0 ≤7.4.8, Fortinet:FortiOS 7.6.0 ≤7.6.3, Fortinet:FortiProxy 7.0.0 ≤7.0.21, Fortinet:FortiProxy 7.2.0 ≤7.2.14, Fortinet:FortiProxy 7.4.0 ≤7.4.10, Fortinet:FortiProxy 7.6.0 ≤7.6.3, Fortinet:FortiSwitchManager 7.0.0 ≤7.0.5, Fortinet:FortiSwitchManager 7.2.0 ≤7.2.6, Fortinet:Multiple Products
Sources
euvd EUVD-2025-202198
cisa.gov CVE-2025-59718

Description

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

References