FortiCloud SSO authentication bypass
Affects FortiOS, FortiProxy, FortiSwitchManager
An unauthenticated attacker can bypass FortiCloud single sign-on by submitting a crafted SAML message, gaining administrative access to the device. The underlying flaw is improper verification of a cryptographic signature. FortiCloud SSO is off in factory settings, but registering a device to FortiCare through the GUI enables it unless an administrator explicitly opts out — which widened exposure considerably across registered deployments.
What the engine did
On 7 January 2026 the clustering run grouped four CISA-sourced advisory documents into a single coherent cluster centred on this vulnerability, with no analyst defining the campaign, the vendor, or the CVE in advance. The grouping formed roughly three weeks after the vulnerability entered CISA's Known Exploited Vulnerabilities catalogue.
- Cluster
- #144
- Documents
- 4
- Clustered
- 2026-01-07