APromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2025-59718 - Fortinet Multiple Products

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advi...

AI Vulnerability ContextCISA KEVFortinet

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2025-59718
Vendor/project
Fortinet
Product
Multiple Products
Vulnerability name
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Date added
2025-12-16
Due date
2025-12-23
Known ransomware campaign use
Unknown
CWE-347

Exploit context

What the vulnerability is about.

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

Source

Where this page information comes from.