cbcvebase.
CVE-2025-59718
published 2025-12-09

CVE-2025-59718: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
66.32%
99.2th percentile
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetforticloud
fortinetfortinet
fortinetfortios
fortinetfortios>= 7.0.0 < 7.0.187.0.18
fortinetfortios7.0.0 – 7.0.17
fortinetfortios>= 7.2.0 < 7.2.127.2.12
fortinetfortios7.2.0 – 7.2.11
fortinetfortios>= 7.4.0 < 7.4.97.4.9
fortinetfortios7.4.0 – 7.4.8
fortinetfortios>= 7.6.0 < 7.6.47.6.4
fortinetfortios7.6.0 – 7.6.3
fortinetfortiproxy
fortinetfortiproxy>= 7.0.0 < 7.0.227.0.22
fortinetfortiproxy7.0.0 – 7.0.21
fortinetfortiproxy>= 7.2.0 < 7.2.157.2.15
fortinetfortiproxy7.2.0 – 7.2.14
fortinetfortiproxy>= 7.4.0 < 7.4.117.4.11
fortinetfortiproxy7.4.0 – 7.4.10
fortinetfortiproxy>= 7.6.0 < 7.6.47.6.4
fortinetfortiproxy7.6.0 – 7.6.3
fortinetfortiswitchmanager
fortinetfortiswitchmanager>= 7.0.0 < 7.0.67.0.6
fortinetfortiswitchmanager7.0.0 – 7.0.5
fortinetfortiswitchmanager>= 7.2.0 < 7.2.77.2.7
fortinetfortiswitchmanager7.2.0 – 7.2.6

Detection & IOCsextracted from sources · hover to see the quote

ip104.28.244.114
ip45.32.216.250
ip104.28.227.105
commandconfig system global set admin-forticloud-sso-login disable end
  • Detect creation of new local admin accounts post-SSO login via logid 0100044547 — watch for cfgpath='system.admin' with unexpected usernames (audit, backup, itadmin, secadmin, support, helpdesk)
  • Alert on FortiGate system config file downloads via GUI (logid 0100032095, action='download') from external or unrecognized IP addresses — this indicates attacker exfiltration of firewall configuration
  • Detect FortiGate SSL VPN settings being enabled or modified via GUI from external IPs — logid 0100044546 with cfgpath='vpn.ssl.settings' is a key post-exploitation persistence indicator
  • Monitor FortiGate logs for creation of SSO forticloud admin accounts — log entries containing 'Object attribute configured(Add system.sso-forticloud-admin @forticloud.com-1)' indicate attacker-created SSO persistence accounts
  • Detect Mimikatz usage on internal hosts following FortiGate compromise — attackers used it to harvest credentials for lateral movement after initial FortiGate access
  • Monitor for PsExec and RDP lateral movement originating from IP addresses in the FortiGate DHCP lease range — unexpected internal IPs in this range authenticating to Windows hosts indicate VPN-based attacker ingress
  • Check for new firewall policy additions (logid 0100044547, cfgpath='firewall.policy', action='Add') shortly after SSO login events as an indicator of attacker-established persistence and access paths
  • ·CVE-2025-59718 only affects devices where FortiCloud SSO is enabled; the feature is NOT enabled by default on devices that are not FortiCare-registered, reducing the attack surface
  • ·FortiOS 7.4.9 and 7.4.10 do NOT fully remediate CVE-2025-59718; exploitation of patched devices running these versions has been confirmed by Fortinet developers
  • ·The vulnerability is applicable to all SAML SSO implementations on affected products, though active exploitation has only been observed via FortiCloud SSO; third-party SAML IdPs and FortiAuthenticator are confirmed NOT impacted
  • ·Attacker IOC accounts ([email protected], [email protected]) and associated Cloudflare IPs may change as Fortinet and Cloudflare take action to neutralize them
  • ·The attacker established initial access approximately two weeks before any visible malicious activity, meaning detection based solely on post-exploitation events will miss the initial compromise window

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.