Skip to content
CC-4724

CC-4724

Digital.Nhs.Uk •[email protected] (NHS Digital) • December 10, 2025

The security advisory address two vulnerabilities that could allow an attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message

The security advisory address two vulnerabilities that could allow an attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message

The following platforms are known to be affected:

Fortinet FortiSwitch Manager

Fortinet has released a security advisory to address two critical vulnerabilities affecting FortiOS, FortiWeb, FortiProxy and FortiSwitchManager. Devices are only vulnerable if the FortiCloud SSO login feature is enabled when registering the device to FortiCare.

CVE-2025-59718 - an 'improper verification of cryptographic signature' vulnerability with - CVSS v3 score: 9.1.

CVE-2025-59719 - an 'improper verification of cryptographic signature' vulnerability with - CVSS v3 score: 9.1.

Affected organisations are encouraged to review the Fortinet PSIRT FG-IR-25-647 and apply the relevant updates as soon as possible.

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

Last edited: 10 December 2025 12:24 pm

Extracted Entities