CVE-2025-59718

● Known-exploited CRITICAL

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, Fo...

Affects 3 products across 2 vendors.

CVSS 3.19.8
EPSS68.3%
Percentile99th
PatchUnknown
Known-exploited since2025-12-16
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-347: CWE-347
Related Attack Patterns (CAPEC)
CAPEC-463 Padding Oracle Crypto Attack
via CWE-347
CAPEC-475 Signature Spoofing by Improper Validation
via CWE-347

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in Fortinet FortiOS and related products allows unauthenticated attackers to bypass FortiCloud SSO login authentication by crafting a SAML response message. This could lead to unauthorized access and compromise of the network, posing significant risks to operational technology environments.

BSID: BS-2025-GLOBAL-270552-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-59718?
A critical vulnerability in Fortinet FortiOS and related products allows unauthenticated attackers to bypass FortiCloud SSO login authentication by crafting a SAML response message. This could lead to unauthorized access and compromise of the network, posing significant risks to operational technology environments.
What is the CVSS score for CVE-2025-59718?
CVE-2025-59718 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 68.3%.
Is CVE-2025-59718 actively exploited?
Yes. CVE-2025-59718 is in the CISA known-exploited catalog (added 2025-12-16). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-59718?
Priority: IMMEDIATE. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-647 PSIRT: [email protected]
What systems are affected by CVE-2025-59718?
CVE-2025-59718 affects: Fortinet, Fortinet, Fortinet, Siemens.
What NERC-CIP standard applies to CVE-2025-59718?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the network, which can compromise the security of electronic security perimeters and control systems.
What IEC 62443 requirement maps to CVE-2025-59718?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a failure in the authentication and authorization mechanisms, which can lead to unauthorized access and control of the system, violating the security requirements for access control.
Vulnerability Details
CVE IDCVE-2025-59718
BSIDBS-2025-GLOBAL-270552-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-12-09
Last Modified2026-06-17
ICS Relevance85%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from improper verification of cryptographic signatures in the SAML response messages. An unauthenticated attacker can craft a malicious SAML response to bypass the FortiCloud SSO login mechanism, gaining unauthorized access to the affected systems. This can lead to full control over the network, potentially allowing further attacks on connected OT devices.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Fortinet Fortios ≥ 7.0.0, ≤ 7.0.17 ≥ 7.2.0, ≤ 7.2.11 ≥ 7.4.0, ≤ 7.4.8 ≥ 7.6.0, ≤ 7.6.3
Fortinet Fortiproxy ≥ 7.0.0, ≤ 7.0.21 ≥ 7.2.0, ≤ 7.2.14 ≥ 7.4.0, ≤ 7.4.10 ≥ 7.6.0, ≤ 7.6.3
Fortinet Fortiswitchmanager ≥ 7.0.0, ≤ 7.0.5 ≥ 7.2.0, ≤ 7.2.6
Siemens — —
Siemens Ruggedcom Ape1808 Firmware All versions
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 300 Days
CISA known-exploited● Active Exploitation Confirmed (added 2025-12-16)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict SAML response validation and monitoring for anomalous authentication attempts. Ensure that all SAML responses are verified against a trusted certificate authority and that any deviations are immediately flagged and investigated.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the network, which can compromise the security of electronic security perimeters and control systems.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a failure in the authentication and authorization mechanisms, which can lead to unauthorized access and control of the system, violating the security requirements for access control.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash01e0e127282958a023c006a80909e9d0f7b1e7f99e6c49d3175fc0a4fe8693fc94cd9958efe3bbe3da1cfb8721f80ab2ca1bab4157c2b76daa4f4393b66dfd8b
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2026-26084 9.9 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 throug... CVE-2017-17539 9.8 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier a... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers... CVE-2020-9294 9.8 An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 an...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-59718 is on the CISA known-exploited list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →