CVE-2025-59718FortiCloud SSO SAML bypass on FortiOS, FortiProxy, FortiSwitchManager
What broke
Fortinet FortiOS, FortiProxy, and FortiSwitchManager accepted a crafted SAML message as a valid FortiCloud SSO login (CWE-347, improper verification of a cryptographic signature). CVSS 9.8. Disclosed 9 December 2025. Arctic Wolf observed malicious SSO logins on FortiGate appliances beginning 12 December, three days later. CISA added CVE-2025-59718 to KEV on 16 December 2025 and set a federal patch-by date of 23 December 2025.
CVE-2025-59719 is the FortiWeb twin. CVE-2026-24858 is the follow-on that hits devices already patched for this pair.
Why it matters
This is the identity CVE that was exploited in the wild fastest in the 2025-2026 window. FortiCloud SSO sits on the management plane of firewalls and proxies. A SAML bypass there is not a user-app account takeover. It is administrative control of the network edge, after which ransomware crews do not need a second exploit.
What to do
- Patch now if FortiCloud SSO is enabled. If you do not need FortiCloud SSO, disable it.
- Hunt for rogue admin accounts and unexpected configuration changes from 12 December 2025 onward (Arctic Wolf's first observed exploitation).
- Do not stop at the 59718/59719 patch. Confirm you are also covered for CVE-2026-24858.
- Treat internet-facing management SSO as tier-zero. The same lesson as the Okta support-system teardown.
Sources
- NVD: CVE-2025-59718
- CISA Known Exploited Vulnerabilities catalog (added 16 December 2025)
- Arctic Wolf, malicious FortiCloud SSO logins from 12 December 2025