# Fortinet's January SSO bypass hit boxes already patched for December's SAML bug

Source: https://startwithidentity.com/blog/2026-08-13-fortinet-sso-follow-on-24858/
Last updated: 2026-08-13
License: content by Start with Identity. Cite the source URL.

---

[CVE-2026-24858](https://startwithidentity.com/cves/cve-2026-24858/) is the leftover FortiCloud SSO [SAML](https://startwithidentity.com/glossary/saml/) path after December 2025's [CVE-2025-59718](https://startwithidentity.com/cves/cve-2025-59718/) / [59719](https://startwithidentity.com/cves/cve-2025-59719/). Arctic Wolf saw malicious FortiCloud logins three days after the first disclosure. CISA put 59718 on KEV with a one-week patch-by date. In January, CISA came back: devices that had taken that patch were still exploitable. Exploitation is in the wild.

This is the incomplete-fix pattern we already documented on ruby-saml and N-central, now on a firewall management plane. "We patched FortiCloud SSO in December" is not a closed ticket. The [SAML protocol page](https://startwithidentity.com/cves/saml/) is the place to put this for a network-and-identity joint review.

## Why it matters

A SAML bypass on the appliance that filters the rest of the network is administrative control of the edge. Attackers who burned 59718 moved to 24858. If FortiCloud SSO is still enabled, disable it unless you have a reason, then confirm the January 2026 build string, not the month you last opened a change window.

Read the [CVE-2026-24858 brief](https://startwithidentity.com/cves/cve-2026-24858/) and re-hunt admin creation from late January 2026.

Source: [NVD: CVE-2026-24858](https://nvd.nist.gov/vuln/detail/CVE-2026-24858)
