CVE-2025-59719

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass

Severity
Critical 9.1
CVSS 3.1
Exploited
Not listed
EPSS
0.240
97.6th percentile
Discovered by
Not disclosed
Published
Dec 9, 2025
Assigned by fortinet

Description

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Weakness: CWE-347

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiWeb
  • Siemens · RUGGEDCOM APE1808

Vendor remediation

Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Upgrade to FortiProxy version 7.6.4 or above Upgrade to FortiProxy version 7.4.11 or above Upgrade to FortiProxy version 7.2.15 or above Upgrade to FortiProxy version 7.0.22 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiOS version 7.0.18 or above Upgrade to FortiWeb version 8.0.1 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Fortinet remediated this issue in FortiSASE version 25.3.b and hence customers do not need to perform any action. Upgrade to FortiPAM version 1.8.0 or above