Emergent ThreatCVE-2025-59718:Critical vulnerabilities in Fortinet CVE-2025-59718, CVE-2025-59719, CVE-2026-24858 exploited in the wildBlog ↗
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Fortinet Fortiweb | — | Upgrade FortiWeb to 7.6.5Upgrade FortiWeb to 7.4.10Upgrade FortiWeb to 8.0.1 | Jun 30, 2026 | Dec 9, 2025 |
| Fortios | — | Upgrade FortiOS to 7.2.12Upgrade FortiOS to 7.0.18Upgrade FortiOS to 7.6.4Upgrade FortiOS to 7.4.9 | Jul 2, 2026 | Dec 9, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub