SecPod

Learn Search

Search across all Learn content

← Back to Security Research
No Credentials Required: FortiGate SAML SSO Exploit Path Explained

No Credentials Required: FortiGate SAML SSO Exploit Path Explained

Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated as CVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an u...

Dec 16, 2025By Santosh Sethuraman4 min read

Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated asCVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an unauthenticated bypass of SAML Single Sign-On (SSO) authentication, granting attackers unauthorized administrative access to the device.

Security researchers have confirmed that these vulnerabilities are under active attack in the wild as of December 12, 2025. This situation poses a severe risk to organizations relying on Fortinet for network perimeter security.

Root Cause Analysis

The root cause of these vulnerabilities lies in the implementation of the FortiCloud Single Sign-On (SSO) feature. While standard authentication mechanisms remain secure, the handling of SAML (Security Assertion Markup Language) messages within the FortiCloud SSO integration is flawed.

Specifically, the vulnerabilities allow an attacker to forge SAML messages. Because the system fails to properly validate these crafted messages, an unauthenticated remote attacker can bypass the login process entirely.

A critical nuance in this configuration is the “default” state of the feature. While Fortinet states that FortiCloud SSO is disabled by default in the firmware, it is automatically enabled during the device’s FortiCare registration process. Unless an administrator explicitly unchecks the “Allow administrative login using FortiCloud SSO” setting during registration, the device becomes vulnerable to this attack vector.

The Exploitation Process

Exploiting CVE-2025-59718 and CVE-2025-59719 allows an attacker to gain administrative access without valid credentials. The observed attack chain typically follows these steps:

  1. Reconnaissance: The attacker identifies a public-facing Fortinet device (FortiGate, FortiWeb, etc.) where the management interface is exposed and FortiCloud SSO is enabled.
  2. SAML Forgery: The threat actor crafts a malicious SAML assertion message designed to trick the authentication mechanism.
  3. Authentication Bypass: The crafted message is sent to the target device. Due to the vulnerability, the device accepts the message as valid, bypassing the standard login prompt.
  4. Access & Execution: The attacker gains access to the administrative GUI. Researchers have observed attackers immediately moving to export device configurations.
  5. Data Exfiltration: The configuration files, which contain hashed passwords, network maps, and policy data, are exfiltrated to attacker-controlled infrastructure.

Affected Products and Versions

The vulnerabilities affect a broad suite of Fortinet’s ecosystem.

The following table details the specific components and versions that require immediate attention:

ProductVulnerable Version RangeFixed Version
FortiOS (FortiGate)7.6.0 through 7.6.37.6.4
7.4.0 through 7.4.87.4.9
7.2.0 through 7.2.117.2.12
7.0.0 through 7.0.177.0.18
FortiProxy7.6.0 through 7.6.37.6.4
7.4.0 through 7.4.107.4.11
7.2.0 through 7.2.147.2.15
7.0.0 through 7.0.217.0.22
FortiWeb8.0.08.0.1
7.6.0 through 7.6.47.6.5
7.4.0 through 7.4.97.4.10
FortiSwitchManager7.2.0 through 7.2.67.2.7
7.0.0 through 7.0.57.0.6

Techniques and Tactics

These vulnerabilities map to several tactics and techniques in the MITRE ATT&CK framework. While the primary vector is Initial Access, the observed behavior involves Collection and Exfiltration.

TacticTechnique IDTechnique NameDescription
Initial AccessT1190Exploit Public-Facing ApplicationAttackers target the exposed management interface to bypass authentication.
Credential AccessT1606Forge Web CredentialsThe core of the exploit involves forging SAML messages to impersonate valid users/admins.
CollectionT1005Data from Local SystemAttackers are observed exporting the full device configuration via the GUI.
ExfiltrationT1048Exfiltration Over Web ServiceStolen configurations are sent to external IP addresses controlled by the threat actors.

Mitigation & Remediation

To address this critical risk, organizations must act immediately. Mere monitoring is insufficient due to the speed at which these exploits are being automated.

Recommended steps for remediation:

  1. Apply Patches: Update FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager to the fixed versions listed in the table above immediately.
  2. Disable FortiCloud SSO: As a temporary workaround until patching is possible, administrators should manually disable the FortiCloud SSO feature on all management interfaces.
  3. Reset Credentials: If you suspect your device was exposed, assume compromise. Attackers extract configuration files containing hashed passwords. These can be cracked offline. Reset all administrative credentials and VPN secrets stored on the device.
  4. Limit Management Access: Ensure that management interfaces (HTTP/HTTPS/SSH) are not exposed to the open internet. Restrict access to trusted internal IP addresses or via a VPN.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026