CVE-2025-59718

Confirmed PUBLISHED

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...

Fortinet · FortiSwitchManager, FortiOS, FortiProxy

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.1 Critical EPSS 65.8%

At a Glance

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

cisa ios edge
CVE Published
Dec 09, 2025
Exploitation Reported
Jun 01, 2026
CVSS
9.1 Critical
EPSS
65.8%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Siemens
RUGGEDCOM APE1808

0 to < *

Affected
Fortinet
FortiSwitchManager

7.2.0 to <= 7.2.6

Affected
Fortinet
FortiSwitchManager

7.0.0 to <= 7.0.5

Affected
Fortinet
FortiOS

7.6.0 to <= 7.6.3

Affected
Fortinet
FortiOS

7.4.0 to <= 7.4.8

Affected
Fortinet
FortiOS

7.2.0 to <= 7.2.11

Affected
Fortinet
FortiOS

7.0.0 to <= 7.0.17

Affected
Fortinet
FortiProxy

7.6.0 to <= 7.6.3

Affected
Fortinet
FortiProxy

7.4.0 to <= 7.4.10

Affected
Fortinet
FortiProxy

7.2.0 to <= 7.2.14

Affected
Fortinet
FortiProxy

7.0.0 to <= 7.0.21

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.