CISA Adds Fortinet Vulnerability to KEV Catalog After Active Exploitation
On December 16, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-59718 to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are required to implement necessary remediation measures by December 23, 2025, due…
On December 16, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-59718 to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are required to implement necessary remediation measures by December 23, 2025, due to the active exploitation and immediate threat posed by this vulnerability.
The vulnerability affects several Fortinet security products, including FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb . It involves improper verification of cryptographic signatures, enabling unauthenticated attackers to bypass FortiCloud Single Sign-On (SSO) authentication through specially crafted SAML messages.
This authentication bypass provides unauthorized network access without valid credentials.
Fortinet has issued advisories addressing the issue, urging administrators to apply all available patches immediately.
Detail Information
CVE ID CVE-2025-59718
The vulnerability affects several Fortinet security products, including FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb .
CWE Classification CWE-347 (Improper Verification of Cryptographic Signature)
Vulnerability Type Authentication Bypass via SAML
Attack Vector Unauthenticated, Network-based
A related vulnerability, CVE-2025-59719 , addresses the same issue and requires comprehensive patching across affected systems.
CISA's inclusion of this vulnerability in the KEV catalog mandates compliance with federal security guidance, particularly for agencies utilizing cloud services. Organizations should adhere to applicable BOD 22-01 guidance when implementing cloud-based Fortinet solutions.
In cases where immediate patch deployment is not feasible, CISA recommends discontinuing product use until mitigations are verified. Active exploitation signifies that threat actors are leveraging this vulnerability in operational attacks.
Security teams should prioritize remediation of CVE-2025-59718 within their patch management cycles, especially for edge security appliances and web application firewalls exposed to the internet.
Organizations using affected Fortinet products should audit their deployment inventory and initiate emergency patching procedures before the December 23 deadline to prevent credential-free network intrusion.
Based on reporting by Cyber Security News.
