Fortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidance 28 January 2026.
CVE-2026-24858 is the leftover FortiCloud SSO SAML path after December 2025's CVE-2025-59718 / 59719. Arctic Wolf saw malicious FortiCloud logins three days after the first disclosure. CISA put 59718 on KEV with a one-week patch-by date. In January, CISA came back: devices that had taken that patch were still exploitable. Exploitation is in the wild.
This is the incomplete-fix pattern we already documented on ruby-saml and N-central, now on a firewall management plane. "We patched FortiCloud SSO in December" is not a closed ticket. The SAML protocol page is the place to put this for a network-and-identity joint review.
Why it matters
A SAML bypass on the appliance that filters the rest of the network is administrative control of the edge. Attackers who burned 59718 moved to 24858. If FortiCloud SSO is still enabled, disable it unless you have a reason, then confirm the January 2026 build string, not the month you last opened a change window.
Read the CVE-2026-24858 brief and re-hunt admin creation from late January 2026.
Source: NVD: CVE-2026-24858
Related on Start with Identity
- BlogKerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN
CVE-2026-25177, CVSS 8.8. Active Directory treated look-alike SPNs as unique. Semperis and Shai Laron showed how that becomes service hijack and NTLM downgrade.
- BlogResetNightmare: a low-priv UPN write can reset a Domain Admin via Kerberos kpasswd
CVE-2026-27912 lets a user who can write their own UPN aim a Kerberos change-password at a Domain Admin. Microsoft rated it Important. Identity teams should not
- BlogQilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session w
- CVEGitHub Enterprise Server SAML bypass via libxml2 canonicalization
GitHub Enterprise Server accepted a crafted SAML response because libxml2 canonicalization quirks let the signed XML and the consumed XML diverge. High-severity
- CVEGitHub Enterprise Server SAML encrypted-assertion bypass
GHES with optional encrypted SAML assertions accepted a forged response. An unauthenticated attacker could provision a site administrator. Fixed in 3.9.15, 3.10
- CVEIvanti Connect Secure SAML SSRF, chained to auth bypass
SSRF in the SAML component of Ivanti Connect Secure and Policy Secure. Attackers chained it with CVE-2023-46805 and CVE-2024-21887 after those were patched. CIS