# FortiCloud SSO SAML bypass on FortiOS, FortiProxy, FortiSwitchManager

Source: https://startwithidentity.com/cves/cve-2025-59718/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Fortinet FortiOS, FortiProxy, and FortiSwitchManager accepted a crafted [SAML](https://startwithidentity.com/glossary/saml/) message as a valid FortiCloud SSO login (CWE-347, improper verification of a cryptographic signature). CVSS 9.8. Disclosed 9 December 2025. Arctic Wolf observed malicious SSO logins on FortiGate appliances beginning 12 December, three days later. CISA added CVE-2025-59718 to KEV on 16 December 2025 and set a federal patch-by date of 23 December 2025.

[CVE-2025-59719](https://startwithidentity.com/cves/cve-2025-59719/) is the FortiWeb twin. [CVE-2026-24858](https://startwithidentity.com/cves/cve-2026-24858/) is the follow-on that hits devices already patched for this pair.

## Why it matters

This is the identity CVE that was exploited in the wild fastest in the 2025-2026 window. FortiCloud SSO sits on the management plane of firewalls and proxies. A SAML bypass there is not a user-app account takeover. It is administrative control of the network edge, after which ransomware crews do not need a second exploit.

## What to do

- Patch now if FortiCloud SSO is enabled. If you do not need FortiCloud SSO, disable it.
- Hunt for rogue admin accounts and unexpected configuration changes from 12 December 2025 onward (Arctic Wolf's first observed exploitation).
- Do not stop at the 59718/59719 patch. Confirm you are also covered for [CVE-2026-24858](https://startwithidentity.com/cves/cve-2026-24858/).
- Treat internet-facing management SSO as tier-zero. The same lesson as the [Okta support-system teardown](https://startwithidentity.com/breaches/okta-2023-support-system-breach/).

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2025-59718](https://nvd.nist.gov/vuln/detail/CVE-2025-59718)
- CISA Known Exploited Vulnerabilities catalog (added 16 December 2025)
- Arctic Wolf, malicious FortiCloud SSO logins from 12 December 2025
