FortiGate CVE-2025-59718 Exploitation: Incident Response Findings

2026-04-09T07:23:46Za70d77e6f50d9149e9f6aa6b3b40540d5266ddfd1f7b67b5cdb901fef9581e39
CVE-2025-59718FortiGateFortinetSSO bypasscontainmentcryptographic signaturedetectionedge device compromiseexploitation in the wildfirewallincident responselateral movement

What happened

Rapid7’s IR team investigated an active exploitation of FortiGate CVE-2025-59718 — an improper verification of cryptographic signature that enables an SSO login bypass on vulnerable FortiGate appliances. Attackers used the flaw to gain initial access, maintained a low-profile presence while compromising additional firewalls, and then moved laterally into internal hosts. Responders were able to contain the intrusion before broader impact. The blog outlines exploitation characteristics, attack progression, and practical detection and response opportunities for defenders.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
a70d77e6f50d9149e9f6aa6b3b40540d5266ddfd1f7b67b5cdb901fef9581e39
Enrichment time
2026-04-09T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.