CVE-2025-59719

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass

Severity
Critical 9.1
CVSS 3.1
Exploited
Not listed
EPSS
0.292
98.1th percentile
Discovered by
Vendor
Vendor advisory field
Published
Dec 9, 2025
Assigned by fortinet

Description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Weakness: CWE-347

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (2)
  • Fortinet · FortiWeb
  • Siemens · RUGGEDCOM APE1808

Credit

Internally discovered and reported by Yonghui Han and Theo Leleu of Fortinet Product Security team.

Vendor remediation

Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to FortiProxy version 7.4.11 or above Upgrade to FortiProxy version 7.2.15 or above Upgrade to FortiProxy version 7.0.22 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiOS version 7.0.18 or above Upgrade to FortiWeb version 8.0.1 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Fortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action. Upgrade to FortiPAM version 1.8.0 or above

Something wrong here?