Cyber Security News

CISA Adds Fortinet Vulnerability to KEV Catalog After Active Exploitation

CISA has officially added CVE-2025-59718 to its Known Exploited Vulnerabilities (KEV) catalog on December 16, 2025.

Designating a critical deadline of December 23, 2025, for organizations to apply necessary remediation measures.

This action reflects the vulnerability’s active exploitation in the wild and the immediate threat it poses to enterprise networks.

The vulnerability affects multiple Fortinet security products, including FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb.

The flaw lies in the improper verification of cryptographic signatures, allowing unauthenticated attackers to bypass FortiCloud Single Sign-On (SSO) authentication via specially crafted SAML messages.

This authentication bypass vulnerability provides a direct path to unauthorized network access without requiring valid credentials.

Fortinet has addressed this issue through vendor advisories, with administrators instructed to apply all available patches immediately.

DetailInformation
CVE IDCVE-2025-59718
CWE ClassificationCWE-347 (Improper Verification of Cryptographic Signature)
Vulnerability TypeAuthentication Bypass via SAML
Attack VectorUnauthenticated, Network-based

A related vulnerability, CVE-2025-59719, pertains to the same underlying issue and is documented in the same advisory, requiring comprehensive patching across affected systems.

The vulnerability is classified under CWE-347 (Improper Verification of Cryptographic Signature), highlighting the specific weakness in the authentication mechanism.

CISA’s inclusion in the KEV catalog mandates compliance with federal security guidance, particularly for agencies operating cloud services.

Organizations must follow applicable BOD 22-01 guidance when implementing cloud-based Fortinet solutions.

For environments where patches cannot be immediately deployed, CISA recommends discontinuing product use until mitigations are available and verified.

The timing of this KEV addition is significant, as active exploitation indicates threat actors are already leveraging this vulnerability in operational attacks.

However, CISA’s current assessment does not conclusively link the vulnerability to ransomware campaigns, though this classification may evolve as threat intelligence develops.

Security teams should prioritize remediation of CVE-2025-59718 within their patch management cycles. Particularly for edge security appliances and web application firewalls that may be directly exposed to the internet.

Organizations running affected Fortinet products should immediately audit their deployment inventory.

And initiate emergency patching procedures before the December 23 deadline to maintain compliance and prevent credential-free network intrusion.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago