CVE-2025-59719: exploitation status and patch state
CVE-2025-59719 · CVSS 9.8 CRITICAL · EPSS 25%
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Is CVE-2025-59719 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 25%.
Public exploit code: none found in monitored sources.