CVE-2025-59718: Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass

Published Dec 9, 2025
·
Updated

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Other sources

An Improper Verification of Cryptographic Signature vulnerability[CWE-347] in FortiOS, FortiWeb, FortiProxy and FortiSwitchManager mayallow an unauthenticated attacker to bypass the FortiCloud SSO loginauthentication via a crafted SAML message, if that feature is enabled on the device. Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch "Allow administrative login using FortiCloud SSO" in the registration page, FortiCloud SSO login is enabled upon registration. To prevent being affected by this vulnerability on vulnerableversions, please turn off the FortiCloud login feature (if enabled) temporarily untilupgrading to a non-affected version.To turn off FortiCloud login, go to System -> Settings -> Switch"Allow administrative login using FortiCloud SSO" to Off. Or type thefollowing command in the CLI: config system global set admin-forticloud-sso-login disableend

FortiGuard

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

CISA

Affected Software

26 affected componentsFixes available
Fortinet FortiOS>=7.6.0<=7.6.3
Fortinet FortiOS>=7.4.0<=7.4.8
Fortinet FortiOS>=7.2.0<=7.2.11
Fortinet FortiOS>=7.0.0<=7.0.17
Fortinet FortiProxy>=7.6.0<=7.6.3
Fortinet FortiProxy>=7.4.0<=7.4.10
Fortinet FortiProxy>=7.2.0<=7.2.14
Fortinet FortiProxy>=7.0.0<=7.0.21
Fortinet FortiSwitchManager>=7.2.0<=7.2.6
Fortinet FortiSwitchManager>=7.0.0<=7.0.5
Fortinet FortiWeb=.
Fortinet FortiWeb>=7.6.0<=7.6.4
Fortinet FortiWeb>=7.4.0<=7.4.9
Fortinet Multiple Products
Fortinet FortiProxy>=7.0.0<7.0.22
Fortinet FortiProxy>=7.2.0<7.2.15
Fortinet FortiProxy>=7.4.0<7.4.11
Fortinet FortiProxy>=7.6.0<7.6.4
Fortinet FortiSwitchManager>=7.0.0<7.0.6
Fortinet FortiSwitchManager>=7.2.0<7.2.7
Fortinet FortiOS>=7.0.0<7.0.18
Fortinet FortiOS>=7.2.0<7.2.12
Fortinet FortiOS>=7.4.0<7.4.9
Fortinet FortiOS>=7.6.0<7.6.4
All of the following
Siemens Ruggedcom Ape1808 Firmware
Siemens Ruggedcom Ape1808

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.0.18
  2. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.2.12
  3. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.4.9
  4. Upgrade

    Upgrade FortiOS to a version that resolves this vulnerability.

    Fixed in 7.6.4
  5. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.0.22
  6. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.2.15
  7. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.4.11
  8. Upgrade

    Upgrade FortiProxy to a version that resolves this vulnerability.

    Fixed in 7.6.4
  9. Upgrade

    Upgrade FortiSwitchManager to a version that resolves this vulnerability.

    Fixed in 7.0.6
  10. Upgrade

    Upgrade FortiSwitchManager to a version that resolves this vulnerability.

    Fixed in 7.2.7
  11. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 7.4.10
  12. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 7.6.5
  13. Upgrade

    Upgrade FortiWeb to a version that resolves this vulnerability.

    Fixed in 8.0.1
  14. Upgrade

    Upgrade FortiPAM to a version that resolves this vulnerability.

    Fixed in 1.8.0
  15. Configuration

    To prevent being affected by vulnerable versions, turn off the FortiCloud login feature temporarily (if enabled) until upgrading. In the GUI registration page, set the toggle switch "Allow administrative login using FortiCloud SSO" to Off. (Also ensure it is disabled on registration.)

    FortiOS / FortiCloud SSO (administrative login) Allow administrative login using FortiCloud SSO = Off
  16. Configuration

    Disable FortiCloud SSO administrative login via CLI: run `config system global` then `set admin-forticloud-sso-login disable`.

    FortiOS (CLI) admin-forticloud-sso-login = disable

Event History

Dec 9, 2025
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·06:36 PM
News Published
via The Register·11:42 PM
News Published
via The Register·11:44 PM
Dec 10, 2025
News Published
via BleepingComputer·06:39 PM
Dec 16, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·03:57 PM
Dec 19, 2025
News Published
via BleepingComputer·03:00 PM
Jan 2, 2026
News Published
via BleepingComputer·04:01 PM
Jan 21, 2026
News Published
via BleepingComputer·05:49 PM
Jan 22, 2026
News Published
via BleepingComputer·11:49 AM
News Published
via The Register·04:07 PM
Jan 23, 2026
News Published
via BleepingComputer·10:39 AM
Jan 27, 2026
News Published
via BleepingComputer·11:19 PM
Jan 28, 2026
News Published
via The Register·04:30 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59718?

CVE-2025-59718 is a critical vulnerability that allows unauthenticated attackers to bypass authentication via a crafted SAML message.

2

How do I fix CVE-2025-59718?

To mitigate CVE-2025-59718, upgrade FortiOS, FortiWeb, FortiProxy, or FortiSwitchManager to the patched versions specified in the advisory.

3

Which Fortinet products are affected by CVE-2025-59718?

CVE-2025-59718 affects FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager across several specified versions.

4

Can CVE-2025-59718 be exploited remotely?

Yes, CVE-2025-59718 can be exploited remotely by unauthenticated attackers if the affected SSO login feature is enabled.

5

Is there a workaround for CVE-2025-59718?

Currently, the recommended solution for CVE-2025-59718 is to update to the latest secure versions of the affected Fortinet products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203