PoC Index

CVE-2025-59719

CRITICAL 9.8EPSS 29.5%

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
29.55% chance of exploitation in the next 30 days, 98th percentile
Published
2025-12-09
Updated
2026-08-11

Proof-of-concept exploits (2)

References

Related