Start with Identity
← Blog
News

Fortinet's January SSO bypass hit boxes already patched for December's SAML bug

CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidance 28 January 2026.

By SWI Community TeamAug 13, 2026

CVE-2026-24858 is the leftover FortiCloud SSO SAML path after December 2025's CVE-2025-59718 / 59719. Arctic Wolf saw malicious FortiCloud logins three days after the first disclosure. CISA put 59718 on KEV with a one-week patch-by date. In January, CISA came back: devices that had taken that patch were still exploitable. Exploitation is in the wild.

This is the incomplete-fix pattern we already documented on ruby-saml and N-central, now on a firewall management plane. "We patched FortiCloud SSO in December" is not a closed ticket. The SAML protocol page is the place to put this for a network-and-identity joint review.

Why it matters

A SAML bypass on the appliance that filters the rest of the network is administrative control of the edge. Attackers who burned 59718 moved to 24858. If FortiCloud SSO is still enabled, disable it unless you have a reason, then confirm the January 2026 build string, not the month you last opened a change window.

Read the CVE-2026-24858 brief and re-hunt admin creation from late January 2026.

Source: NVD: CVE-2026-24858

Independent analysis. No vendor sponsorship.