FortiCloud SSO authentication bypass
Affects FortiOS, FortiProxy, FortiSwitchManager
An unauthenticated attacker can bypass FortiCloud single sign-on by submitting a crafted SAML message, gaining administrative access to the device. The flaw is an improper verification of a cryptographic signature. FortiCloud SSO is disabled in factory settings, but registering a device to FortiCare through the GUI turns it on unless an administrator explicitly opts out — which widened exposure considerably across registered deployments.
What the engine did
On 7 January 2026 the clustering run grouped four CISA-sourced advisory documents into a single coherent cluster centred on this vulnerability, without any analyst defining the campaign, the vendor, or the CVE in advance. The grouping formed roughly three weeks after the vulnerability entered CISA's Known Exploited Vulnerabilities catalogue.
- Cluster
- #144
- Documents
- 4
- Clustered
- 2026-01-07