Emergent ThreatCVE-2025-59718:Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wildBlog ↗
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiweb | — | Upgrade to the latest version of FortiWeb | Jun 30, 2026 | Dec 9, 2025 |
| Fortios | — | Upgrade FortiOS to 7.4.9Upgrade FortiOS to 7.6.4Upgrade FortiOS to 7.0.18Upgrade FortiOS to 7.2.12 | Dec 17, 2025 | Dec 9, 2025 |
| Fortiproxy | — | Upgrade to the latest version of Fortinet FortiProxy | Dec 17, 2025 | Dec 9, 2025 |
| Fortiswitch Manager | — | Upgrade FortiSwitchManager to the latest version | Dec 18, 2025 | Dec 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub