FortiGate CVE-2025-59718 Exploitation: Incident Response Findings
2026-04-09T07:23:46Z•a70d77e6f50d9149e9f6aa6b3b40540d5266ddfd1f7b67b5cdb901fef9581e39
CVE-2025-59718FortiGateFortinetSSO bypasscontainmentcryptographic signaturedetectionedge device compromiseexploitation in the wildfirewallincident responselateral movement
What happened
Rapid7’s IR team investigated an active exploitation of FortiGate CVE-2025-59718 — an improper verification of cryptographic signature that enables an SSO login bypass on vulnerable FortiGate appliances. Attackers used the flaw to gain initial access, maintained a low-profile presence while compromising additional firewalls, and then moved laterally into internal hosts. Responders were able to contain the intrusion before broader impact. The blog outlines exploitation characteristics, attack progression, and practical detection and response opportunities for defenders.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- a70d77e6f50d9149e9f6aa6b3b40540d5266ddfd1f7b67b5cdb901fef9581e39
- Enrichment time
- 2026-04-09T07:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.