Improper verification of cryptographic signature in Fortinet, Inc products - CVE-2026-24858

 

Improper verification of cryptographic signature in Fortinet, Inc products - CVE-2026-24858

Published: January 23, 2026 / Updated: February 13, 2026


Vulnerability identifier: #VU121971
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24858
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass SSO authentication.

The vulnerability exists due to improper verification of cryptographic signature when handling SAML messages. A remote non-authenticated attacker can bypass the FortiCloud SSO login authentication via a crafted SAML message. 

Successful exploitation of the vulnerability requires that the FortiCloud SSO feature is enabled on the device. However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch "Allow administrative login using FortiCloud SSO" in the registration page, FortiCloud SSO login is enabled upon registration.

This vulnerability exists due to incomplete fix for #VU119694 (CVE-2025-59718) and #VU119696 (CVE-2025-59719).

Note, the vulnerability is being actively exploited in the wild.


Affected software

FortiAnalyzer
FortiOS
FortiProxy
FortiSwitch Manager

How to mitigate CVE-2026-24858

Install update from vendor's website.

FortiAnalyzer - addressed in versions 7.0.16, 7.2.12, 7.4.10, 7.6.6
FortiOS - addressed in versions 7.0.19, 7.2.13, 7.4.11, 7.6.6
FortiProxy - addressed in versions 7.4.13, 7.6.6
FortiSwitch Manager - addressed in versions 7.0.16, 7.2.13, 7.4.10, 7.6.6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins