INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Multiple sectors HIGH 1h Global insider Cybersecurity Services CRITICAL 1h Global ransomware Multiple sectors (U.S. companies) CRITICAL 1h Global malware Financial Services, Cryptocurrency CRITICAL 2h Global malware Technology and Cloud Services HIGH 2h Global general Financial Services and E-commerce MEDIUM 2h Global data_breach Social Media and Communications CRITICAL 2h Global general Cybersecurity Operations HIGH 3h Global phishing Technology and Consumer Services HIGH 3h Global data_breach Multiple sectors HIGH 3h Global phishing Multiple sectors HIGH 1h Global insider Cybersecurity Services CRITICAL 1h Global ransomware Multiple sectors (U.S. companies) CRITICAL 1h Global malware Financial Services, Cryptocurrency CRITICAL 2h Global malware Technology and Cloud Services HIGH 2h Global general Financial Services and E-commerce MEDIUM 2h Global data_breach Social Media and Communications CRITICAL 2h Global general Cybersecurity Operations HIGH 3h Global phishing Technology and Consumer Services HIGH 3h Global data_breach Multiple sectors HIGH 3h Global phishing Multiple sectors HIGH 1h Global insider Cybersecurity Services CRITICAL 1h Global ransomware Multiple sectors (U.S. companies) CRITICAL 1h Global malware Financial Services, Cryptocurrency CRITICAL 2h Global malware Technology and Cloud Services HIGH 2h Global general Financial Services and E-commerce MEDIUM 2h Global data_breach Social Media and Communications CRITICAL 2h Global general Cybersecurity Operations HIGH 3h Global phishing Technology and Consumer Services HIGH 3h Global data_breach Multiple sectors HIGH 3h
Vulnerabilities

CVE-2025-59718

Critical 🇺🇸 CISA KEV ⚡ Exploit Available
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability (CVE-2025-59718)
Published: Dec 16, 2025  ·  Source: CISA_KEV
CVSS v3
9.0
🔗 NVD Official
📄 Description (English)

Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability — Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor advisory. Ensure to apply all patches mentioned in the advisory.

🤖 AI Executive Summary

Fortinet multiple products contain an improper cryptographic signature verification vulnerability allowing unauthenticated attackers to bypass FortiCloud SSO authentication via crafted SAML messages. This critical vulnerability affects FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb with a CVSS score of 9.0.

📄 Description (Arabic)

تحتوي منتجات Fortinet على ثغرة في التحقق من التوقيع التشفيري للرسائل SAML المستخدمة في مصادقة FortiCloud SSO. يمكن للمهاجمين غير المصرحين استغلال هذه الثغرة لتجاوز آليات المصادقة عن طريق إرسال رسائل SAML مزيفة. تؤثر الثغرة على عدة منتجات Fortinet الحرجة بما في ذلك جدران الحماية والمحاولات.

🤖 ملخص تنفيذي (AI)

منتجات Fortinet المتعددة تحتوي على ثغرة في التحقق من التوقيع التشفيري غير الصحيح مما يسمح للمهاجمين غير المصرحين بتجاوز مصادقة FortiCloud SSO عبر رسائل SAML مصنوعة. تؤثر هذه الثغرة الحرجة على FortiOS و FortiSwitchMaster و FortiProxy و FortiWeb برقم CVSS 9.0.

🤖 AI Intelligence Analysis Analyzed: Apr 15, 2026 07:54
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking telecom energy government healthcare
⚖️ Saudi Risk Score (AI)
9.0
/ 10.0
🔧 Remediation Steps (English)
Immediately apply all security patches provided by Fortinet for affected products (FortiOS, FortiSwitchMaster, FortiProxy, FortiWeb). Disable FortiCloud SSO temporarily if patches cannot be applied immediately. Implement network segmentation to restrict access to affected systems. Monitor authentication logs for suspicious SAML messages and failed login attempts. Verify SAML message integrity through additional validation mechanisms. Also apply patches for CVE-2025-59719 as mentioned in the vendor advisory.
🔧 خطوات المعالجة (العربية)
طبق فوراً جميع تصحيحات الأمان المقدمة من Fortinet للمنتجات المتأثرة. عطل FortiCloud SSO مؤقتاً إذا لم يكن من الممكن تطبيق التصحيحات فوراً. طبق تقسيم الشبكة لتقييد الوصول للأنظمة المتأثرة. راقب سجلات المصادقة للرسائل المريبة. تحقق من سلامة رسائل SAML من خلال آليات التحقق الإضافية. طبق أيضاً تصحيحات CVE-2025-59719.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1 5.2.2 5.3.1
🔵 SAMA CSF
AC-2 AC-3 AC-4 IA-2 IA-5 IA-7
🟡 ISO 27001:2022
A.9.2.1 A.9.2.2 A.9.2.4 A.9.2.5 A.9.4.2 A.9.4.3
🔗 References & Sources 0
No references.
📦 Affected Products / CPE 1 entries
Fortinet:Multiple Products
📊 CVSS Score
9.0
/ 10.0 — Critical
📋 Quick Facts
Severity Critical
CVSS Score9.0
EPSS2.41%
Exploit ✓ Yes
Patch ✓ Yes
CISA KEV🇺🇸 Yes
KEV Due Date2025-12-23
Published 2025-12-16
Source Feed cisa_kev
Views 1
🇸🇦 Saudi Risk Score
9.0
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
kev actively-exploited
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.