Fortinet disclosed CVE-2026-24858, a critical authentication bypass (CVSS 9.8, CWE-288: Alternate Authentication Path) affecting Fortinet products that support FortiCloud SSO. When FortiCloud SSO is enabled, an attacker with a FortiCloud account and a registered device can potentially authenticate to other organizations’ devices registered to different FortiCloud accounts, effectively bypassing expected administrative authentication controls.
Fortinet reported in-the-wild exploitation prior to patch availability, attributing activity to two attacker-controlled FortiCloud accounts that were subsequently blocked. Impacted versions include FortiAnalyzer (7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5), FortiManager (7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5), and FortiOS (7.0.0–7.0.18, 7.2.0–7.2.12, 7.4.0–7.4.10, 7.6.0–7.6.5), with fixed releases available in the corresponding patched branches. Recommended actions include urgent patching, disabling FortiCloud SSO where feasible, and reviewing authentication/audit logs for anomalous FortiCloud SSO login activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Fortinet started releasing fixed versions and emergency updates for affected products including FortiAnalyzer, FortiManager, FortiOS, and FortiProxy, while additional product impact remained under investigation. The company advised customers to upgrade urgently or disable FortiCloud SSO until patching was complete.
CISA added the Fortinet authentication-bypass flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. The agency also set a January 30, 2026 remediation deadline for U.S. FCEB agencies and urged defenders to hunt for compromise indicators.
Fortinet published advisory FG-IR-26-060 for CVE-2026-24858 and restored FortiCloud SSO with controls blocking logins from vulnerable product versions. The change made upgrades necessary for customers who wanted to continue using FortiCloud SSO safely.
As an emergency mitigation against ongoing exploitation, Fortinet temporarily disabled FortiCloud SSO on the cloud side for affected devices. This was intended to stop malicious logins while the company prepared broader protections and fixes.
Fortinet said CVE-2026-24858 was exploited in the wild by two attacker-controlled FortiCloud accounts. The company blocked those accounts after observing post-compromise actions such as local admin creation, firewall or VPN changes, and configuration downloads.
Arctic Wolf reported an automated attack cluster targeting FortiGate devices beginning around January 15, 2026. The activity involved rapid account creation, VPN enablement, configuration exfiltration, and techniques resembling earlier SSO-bypass exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcedarkreading.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.