Fortinet Vulnerability_CVE-2025-59718 -CVE-2025-59719

Release Date: 9th of December 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

 

  • CVE-2025-59718: This vulnerability involves improper verification of cryptographic signatures in versions of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.
  • CVE-2025-59719: This vulnerability involves improper verification of cryptographic signatures in Fortinet FortiWeb, which could allow an unauthenticated attacker to bypass FortiCloud SSO login authentication via a crafted SAML response message.

 

Read more

 

References

  1. https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-multiple-fortinet-products-forticloud-sso-login-authentication-bypass
  2. https://fortiguard.fortinet.com/psirt/FG-IR-25-647
  3. https://arcticwolf.com/resources/blog/cve-2025-59718-and-cve-2025-59719/
  4. https://thehackernews.com/2025/12/fortinet-ivanti-and-sap-issue-urgent.html