An Improper Verification of Cryptographic Signature vulnerability in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message, if that feature is enabled on the device.
A partial list of potentially affected Fortinet-related assets is outlined in this post.
References:

