SecPod

Learn Search

Search across all Learn content

← Back to Security Research
No Credentials Required: FortiGate SAML SSO Exploit Path Explained

No Credentials Required: FortiGate SAML SSO Exploit Path Explained

Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated as CVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an u...

Dec 16, 2025By Santosh Sethuraman4 min read

Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated asCVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an unauthenticated bypass of SAML Single Sign-On (SSO) authentication, granting attackers unauthorized administrative access to the device.

Security researchers have confirmed that these vulnerabilities are under active attack in the wild as of December 12, 2025. This situation poses a severe risk to organizations relying on Fortinet for network perimeter security.

Root Cause Analysis

The root cause of these vulnerabilities lies in the implementation of the FortiCloud Single Sign-On (SSO) feature. While standard authentication mechanisms remain secure, the handling of SAML (Security Assertion Markup Language) messages within the FortiCloud SSO integration is flawed.

Specifically, the vulnerabilities allow an attacker to forge SAML messages. Because the system fails to properly validate these crafted messages, an unauthenticated remote attacker can bypass the login process entirely.

A critical nuance in this configuration is the “default” state of the feature. While Fortinet states that FortiCloud SSO is disabled by default in the firmware, it is automatically enabled during the device’s FortiCare registration process. Unless an administrator explicitly unchecks the “Allow administrative login using FortiCloud SSO” setting during registration, the device becomes vulnerable to this attack vector.

The Exploitation Process

Exploiting CVE-2025-59718 and CVE-2025-59719 allows an attacker to gain administrative access without valid credentials. The observed attack chain typically follows these steps:

  1. Reconnaissance: The attacker identifies a public-facing Fortinet device (FortiGate, FortiWeb, etc.) where the management interface is exposed and FortiCloud SSO is enabled.
  2. SAML Forgery: The threat actor crafts a malicious SAML assertion message designed to trick the authentication mechanism.
  3. Authentication Bypass: The crafted message is sent to the target device. Due to the vulnerability, the device accepts the message as valid, bypassing the standard login prompt.
  4. Access & Execution: The attacker gains access to the administrative GUI. Researchers have observed attackers immediately moving to export device configurations.
  5. Data Exfiltration: The configuration files, which contain hashed passwords, network maps, and policy data, are exfiltrated to attacker-controlled infrastructure.

Affected Products and Versions

The vulnerabilities affect a broad suite of Fortinet’s ecosystem.

The following table details the specific components and versions that require immediate attention:

ProductVulnerable Version RangeFixed Version
FortiOS (FortiGate)7.6.0 through 7.6.37.6.4
7.4.0 through 7.4.87.4.9
7.2.0 through 7.2.117.2.12
7.0.0 through 7.0.177.0.18
FortiProxy7.6.0 through 7.6.37.6.4
7.4.0 through 7.4.107.4.11
7.2.0 through 7.2.147.2.15
7.0.0 through 7.0.217.0.22
FortiWeb8.0.08.0.1
7.6.0 through 7.6.47.6.5
7.4.0 through 7.4.97.4.10
FortiSwitchManager7.2.0 through 7.2.67.2.7
7.0.0 through 7.0.57.0.6

Techniques and Tactics

These vulnerabilities map to several tactics and techniques in the MITRE ATT&CK framework. While the primary vector is Initial Access, the observed behavior involves Collection and Exfiltration.

TacticTechnique IDTechnique NameDescription
Initial AccessT1190Exploit Public-Facing ApplicationAttackers target the exposed management interface to bypass authentication.
Credential AccessT1606Forge Web CredentialsThe core of the exploit involves forging SAML messages to impersonate valid users/admins.
CollectionT1005Data from Local SystemAttackers are observed exporting the full device configuration via the GUI.
ExfiltrationT1048Exfiltration Over Web ServiceStolen configurations are sent to external IP addresses controlled by the threat actors.

Mitigation & Remediation

To address this critical risk, organizations must act immediately. Mere monitoring is insufficient due to the speed at which these exploits are being automated.

Recommended steps for remediation:

  1. Apply Patches: Update FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager to the fixed versions listed in the table above immediately.
  2. Disable FortiCloud SSO: As a temporary workaround until patching is possible, administrators should manually disable the FortiCloud SSO feature on all management interfaces.
  3. Reset Credentials: If you suspect your device was exposed, assume compromise. Attackers extract configuration files containing hashed passwords. These can be cracked offline. Reset all administrative credentials and VPN secrets stored on the device.
  4. Limit Management Access: Ensure that management interfaces (HTTP/HTTPS/SSH) are not exposed to the open internet. Restrict access to trusted internal IP addresses or via a VPN.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026