Executive brief
A vulnerability exists in several Fortinet networking products, including the FortiOS operating system used in firewalls. This flaw allows an unauthorized person to bypass the login screen and gain administrative access to the device by sending a specially crafted message. If exploited, an attacker could take full control of the network equipment, potentially leading to data theft, network outages, or further attacks on the internal corporate network.
Technical details
The vulnerability (CWE-347) is caused by the improper verification of cryptographic signatures within the SAML authentication process. An unauthenticated, remote attacker can exploit this by sending a specially crafted SAML response message to the affected device's management interface. If the 'FortiCloud SSO login' feature is enabled (which may occur automatically during FortiCare registration), the attacker can bypass authentication and gain administrative access. The vulnerability has been observed being exploited in the wild. Patches are available in FortiOS 7.6.4, 7.4.9, 7.2.12, and 7.0.18, with similar updates for other affected product lines.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17
- Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4.0 through 7.4.10, 7.2.0 through 7.2.14, 7.0.0 through 7.0.21
- Fortinet FortiSwitchManager 7.2.0 through 7.2.6, 7.0.0 through 7.0.5
- Fortinet FortiWeb 8.0.0, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9
- Siemens RUGGEDCOM APE1808 (Fortinet NGFW) Versions with Fortinet NGFW < V7.4.9 or < V7.6.6
Timeline
- 2025-12-09: disclosed: Initial publication by Fortinet
- 2025-12-12: exploited: Arctic Wolf observed active exploitation in the wild
- 2025-12-16: kev added: Added to CISA Known Exploited Vulnerabilities catalog