


Perceptive Security
SOC/SIEM Consultancy

Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauth…
Published:
16 december 2025 om 00:00:00
Alert date:
16 december 2025 om 19:00:38
Source:
cisa.gov
Multiple Fortinet products including FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability. This flaw allows unauthenticated attackers to bypass FortiCloud SSO login authentication through crafted SAML messages. The vulnerability is classified as high severity and affects critical network security infrastructure. CVE-2025-59719 relates to the same issue and is covered in the same vendor advisory. Organizations should prioritize patching these vulnerabilities due to their potential impact on authentication systems.
Technical details
Mitigation steps:
Affected products:
FortiOS
FortiSwitchMaster
FortiProxy
FortiWeb
Related links:
https://docs.fortinet.com/upgrade-tool/fortigate
https://fortiguard.fortinet.com/psirt/FG-IR-25-647
https://nvd.nist.gov/vuln/detail/CVE-2025-59718
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
