Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
High Listed in CISA KEV
Summary
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Fortinet:Multiple Products
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-59718 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://fortiguard.fortinet.com/psirt/FG-IR-25-647 reference
- https://docs.fortinet.com/upgrade-tool/fortigate reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV