CVE-2025-59718: FortiCloud SSO Trust Failure Enables Unauthenticated Admin Access

Overview

CVE-2025-59718 is a critical authentication bypass vulnerability affecting several Fortinet products that rely on FortiCloud Single Sign-On (SSO) for administrative access. When FortiCloud SSO is enabled, the vulnerability allows an unauthenticated remote attacker to gain full administrative control of the affected device by sending specially crafted SAML authentication messages.

The root of the issue lies in how cryptographic signatures within SAML messages are validated. Due to improper verification, malicious authentication assertions can be accepted as legitimate. This allows attackers to bypass all normal login checks without providing valid credentials.

Active exploitation of this vulnerability was observed beginning December 12, 2025, only days after Fortinet released security patches. In response to confirmed attacks and the severity of the impact, CISA added CVE-2025-59718 to the Known Exploited Vulnerabilities (KEV) catalog on December 16, 2025, with a mandatory remediation deadline of December 23, 2025 for federal agencies.


Vulnerability Summary

Classification, Severity, and Exploitability

  • CVE ID: CVE-2025-59718
  • Severity (CVSS v3.1): 9.8 – Critical
  • Severity (CVSS v2): 10.0 – Critical
  • Weakness Classification:
    CWE-347 – Improper Verification of Cryptographic Signature
  • Affected Vendors: Fortinet
  • Affected Features: FortiCloud Single Sign-On (SSO) administrative login
  • Related Vulnerability:
    CVE-2025-59719 (affects FortiWeb only and addressed in the same advisory)
  • Exploitability:Yes – Actively Exploited
    • Remote exploitation is possible
    • No authentication is required
    • No user interaction is required
    • Exploitation complexity is low once SAML message structure is understood

The vulnerability allows attackers to directly access administrative interfaces, making it one of the highest-risk classes of flaws for perimeter security devices.


Affected Products and Versions

The vulnerability affects multiple Fortinet products only when FortiCloud SSO login is enabled.

FortiOS

  • 7.6.0 to 7.6.3 → Fixed in 7.6.4 or later
  • 7.4.0 to 7.4.8 → Fixed in 7.4.9 or later
  • 7.2.0 to 7.2.11 → Fixed in 7.2.12 or later
  • 7.0.0 to 7.0.17 → Fixed in 7.0.18 or later
  • 6.4.x → Not affected

FortiProxy

  • 7.6.0 to 7.6.3 → Fixed in 7.6.4 or later
  • 7.4.0 to 7.4.10 → Fixed in 7.4.11 or later
  • 7.2.0 to 7.2.14 → Fixed in 7.2.15 or later
  • 7.0.0 to 7.0.21 → Fixed in 7.0.22 or later

FortiSwitchManager

  • 7.2.0 to 7.2.6 → Fixed in 7.2.7 or later
  • 7.0.0 to 7.0.5 → Fixed in 7.0.6 or later

FortiWeb

  • 8.0.0 → Fixed in 8.0.1 or later
  • 7.6.0 to 7.6.4 → Fixed in 7.6.5 or later
  • 7.4.0 to 7.4.9 → Fixed in 7.4.10 or later

Root Cause Explanation

The vulnerability is caused by incorrect validation of cryptographic signatures in SAML (Security Assertion Markup Language) messages used during FortiCloud SSO authentication.

Under normal conditions, SAML assertions are digitally signed to ensure they come from a trusted identity provider. In affected Fortinet products, this signature verification is not properly enforced. As a result, a forged SAML message can be accepted as valid even though it was not issued by FortiCloud.

Key Technical Characteristics

  • Attack Vector: Network-based
  • Authentication Required: None
  • Privileges Required: None
  • Attack Complexity: Low

This flaw effectively removes the trust boundary between the Fortinet device and the identity provider.


Exploitation Conditions

The vulnerability is only exploitable when FortiCloud SSO is enabled.

While FortiCloud SSO is not enabled by default on factory-installed systems, it is commonly activated unintentionally. When administrators register a device with FortiCare through the device GUI, the option “Allow administrative login using FortiCloud SSO” is automatically enabled unless it is manually disabled.

As a result, many organizations may be exposed without realizing that SSO-based administrative access has been turned on.


How the Vulnerability Is Exploited

Attackers exploit the vulnerability by crafting malicious SAML authentication messages that bypass cryptographic signature checks.

By submitting these forged messages to the FortiCloud SSO login endpoint, attackers can:

  • Successfully authenticate as an administrator
  • Gain access to the device management interface
  • Execute administrative actions without detection

Because the authentication process itself is bypassed, traditional protections such as strong passwords or multi-factor authentication do not provide protection in this scenario.


Security Impact

Successful exploitation allows attackers to:

  • Completely bypass authentication controls
  • Gain full administrative access to the device
  • Download configuration files, exposing credentials, VPN keys, certificates, and routing details
  • Modify firewall and security policies
  • Create persistent backdoors, including new administrator accounts
  • Use the compromised device as a launch point for further network intrusion

Given the role these devices play at network perimeters, compromise can have organization-wide consequences.


Active Exploitation Details

Observed Attack Activity

Security researchers at Arctic Wolf confirmed active exploitation beginning December 12, 2025, shortly after Fortinet released patches on December 9, 2025.

Observed attack activity included:

  • Malicious FortiCloud SSO login attempts
  • Forged SAML authentication requests
  • Unauthorized administrative access to FortiGate and related appliances

The speed of exploitation strongly suggests that threat actors were monitoring patch releases and rapidly weaponized the vulnerability.


CISA KEV Catalog Inclusion

  • Date Added: December 16, 2025
  • Remediation Deadline: December 23, 2025

Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to remediate this vulnerability by the stated deadline. CISA has identified this flaw as posing an immediate threat to enterprise and government networks.


Official Fortinet Advisory

  • Advisory ID: FG-IR-25-647
  • Publication Date: December 9, 2025
  • Discovered By: Yonghui Han and Theo Leleu, Fortinet Product Security Team

Fortinet confirmed that improper cryptographic signature validation allows unauthenticated attackers to bypass FortiCloud SSO authentication through crafted SAML messages when the feature is enabled.


Mitigation and Remediation

Immediate Workaround (If Patching Is Delayed)

Fortinet recommends disabling FortiCloud SSO login until patches can be applied.

GUI Method:
System → Settings → Disable Allow administrative login using FortiCloud SSO

CLI Method:

config system global
set admin-forticloud-sso-login disable
end

Permanent Remediation

All affected systems should be upgraded to the fixed versions listed above. CISA guidance emphasizes applying all patches referenced in the Fortinet advisory, including those addressing CVE-2025-59719.


Detection and Investigation Guidance

Organizations should:

  • Identify all Fortinet devices with FortiCloud SSO enabled
  • Review administrative and authentication logs for unusual SSO activity
  • Check whether configuration files may have been accessed or exported
  • Be aware that exploitation may leave minimal logging evidence, making detection challenging

Risk Context

Fortinet authentication bypass vulnerabilities have historically been targeted by ransomware operators, espionage groups, and nation-state actors, including campaigns such as Volt Typhoon.

Any Fortinet device registered with FortiCare and using FortiCloud SSO should be considered high risk until patched or mitigated, particularly firewalls, proxies, and web application firewalls positioned at the network edge.


Final Takeaway

CVE-2025-59718 is a severe and actively exploited vulnerability that directly undermines administrative authentication in Fortinet products using FortiCloud SSO. Because exploitation requires no credentials and grants immediate administrative access, the risk to affected organizations is significant.

Devices exposed to the internet or registered with FortiCare are especially vulnerable if FortiCloud SSO remains enabled. The combination of low exploitation complexity, confirmed real-world attacks, and high-impact outcomes makes this issue a top-priority remediation item.

Organizations should act immediately to patch affected systems or disable FortiCloud SSO, review administrative access for signs of compromise, and treat any unpatched device as potentially exposed until remediation is complete.

Aegiron

Backed by 11+ years in cybersecurity and incident response, we decode the latest threats shaping today’s digital battlefield. This blog cuts through the noise with clear insights on vulnerabilities, emerging exploits, and the cyber news defenders can’t afford to miss.