{
  "id": "CVE-2025-59718",
  "url": "https://spydr.io/cve/CVE-2025-59718",
  "published": "2025-12-09T18:15:54.983Z",
  "modified": "2026-06-17T09:46:35.807Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "fortinet.com",
  "epss": 0.68293,
  "epss_percentile": 0.99315,
  "exploited": true,
  "kev": {
    "added": "2025-12-16",
    "due": "2025-12-23",
    "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "ransomware": "Unknown",
    "name": "Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability",
    "notes": "https://fortiguard.fortinet.com/psirt/FG-IR-25-647 ; https://docs.fortinet.com/upgrade-tool/fortigate ; https://nvd.nist.gov/vuln/detail/CVE-2025-59718"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Fortinet",
    "Siemens"
  ],
  "products": [
    "Fortinet FortiSwitchManager",
    "Fortinet FortiOS",
    "Fortinet FortiProxy",
    "Siemens RUGGEDCOM APE1808"
  ],
  "cwes": [
    "CWE-347"
  ],
  "description": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://fortiguard.fortinet.com/psirt/FG-IR-25-647",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-864900.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59718",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59718",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
