#saml-authentication-bypass

[ follow ]
fromTheregister
1 day ago

Fortinet SSO patch bypass gets a separate critical CVE

Those hoping for a reprieve following last week's patch pantomime are out of luck. After users reported successful compromises of FortiCloud SSO accounts, despite being patched against an earlier flaw, the vendor confirmed there was an alternate attack path. According to a security advisory published Tuesday, that alternate path was assigned a separate vulnerability identifier (CVE-2026-24858, CVSS 9.4), and the company disabled FortiCloud SSO connections made from vulnerable versions.
Information security
Information security
fromTheregister
6 days ago

FortiGate SSO bug still exploitable despite December patch

Attackers have found a new way to bypass Fortinet's December patch for FortiCloud SSO, enabling compromise of updated FortiGate devices and exfiltration of configurations.
[ Load more ]